Platform security
Security practices and review results
MemeAssist publishes the scope, outcome and limitations of its application-security checks so users can judge the evidence rather than rely on an unsupported badge.
Last reviewed: 26 August 2026
Review scope and results
- Dependency audit: six initial advisories were remediated. The rerun found zero critical, high, moderate, low or informational dependency vulnerabilities.
- Static analysis: Semgrep reported three medium dynamic-redirect warnings. The targets are relative MemeAssist URLs, and hostile-parameter probes stayed on-origin. The warnings remain documented as reviewed, non-exploitable false positives.
- Privacy and dataflow: HoundDog reported zero findings in the reviewed code.
- Black-box checks: no exploitable reflected XSS in token URLs or search, path traversal exposure, unauthenticated admin API access, or secret and stack-trace leakage was found in the tested public surface.
- Browser hardening: CSP, anti-framing, MIME-sniffing, referrer and permissions headers were added after the review identified they were missing.
Unresolved severity summary: zero critical and zero high findings. The three medium static-analysis warnings described above remain documented; no low dependency or privacy/dataflow findings were reported.
Methods, tools and limitations
The focused review covered the public Token Intelligence website and API. Checks used Replit Security Agent scanners incorporating an OSV dependency audit, Semgrep static analysis and HoundDog privacy/dataflow analysis. A task-agent browser performed focused, non-destructive black-box checks.
Limitations: This was a focused review, not an independent audit or certification. Automated tools and bounded black-box checks cannot prove the absence of every vulnerability. Results describe the tested code and surface on the review date. MemeAssist does not claim tool-provider partnership, continuous monitoring or that no code is shared with tool providers.
Data handling
MemeAssist analyzes public token addresses and on-chain market data. Using the public analyzer does not require connecting a crypto wallet. When you create an account, Clerk handles your email address and basic profile information.
MemeAssist also stores service activity needed to provide reports, usage limits and alerts. Necessary processors support authentication, email, hosting and AI-assisted token analysis; AI providers receive token data rather than personal profile details. See the Privacy Policy for retention, deletion and user-rights details. A zero-finding HoundDog scan does not mean MemeAssist collects no data.
Responsible disclosure
If you believe you have found a security issue, email admin@memeassist.com with enough detail to reproduce it. Please allow time for investigation and remediation before public disclosure.