Quantum Audit Logo

Is Tajir Safe?

On-chain security analysis — is it a scam or legit?

Is this your token? Publish your own audit on this page →

Tajir TJR
0x9d98…c110
Ethereum
Not verifiedThis record has not gone through deep verification and is not being monitored. The score is a dated snapshot — the token’s risk can change at any time.Own this token? Put it under verification →
Last checked today 1 audit on record
How is this score calculated? → Medium Risk
Executive SummaryAI Copilot

The TajirToken contract is an upgradeable ERC-20 token utilizing the UUPS proxy pattern and OpenZeppelin's AccessControl for administrative functions. No critical or high-severity vulnerabilities were identified during this audit based on the provided code map and analysis.

6 Informational
Volume 24h
$67.1K
Liquidity
$97.9K
Price
$0.3626
Token Age
7d
Top 10 Holders
100.0%

Security Findings

Info

No issues identified in the reviewed source

I-01The verified source code was reviewed and no issue rising to Informational severity or above was identified. This is a statement about the code that was read, not a guarantee: the review covers the published source only. Fact-layer checks (mint capability, holder concentration) were applied separately and feed the risk score.
IssueThe verified source code was reviewed and no issue rising to Informational severity or above was identified. This is a statement about the code that was read, not a guarantee: the review covers the published source only. Fact-layer checks (mint capability, holder concentration) were applied separately and feed the risk score.
FixRe-check after any contract upgrade or ownership change, both of which can alter behaviour without changing this page.
StatusAcknowledged
Info

Who holds the supply

QA-HOLDERSThe ten largest holders own 100.0% of supply. What remains: 0.0% in wallets, 100.0% in other contracts. 1 holders in total.
IssueThe ten largest holders own 100.0% of supply. What remains: 0.0% in wallets, 100.0% in other contracts. 1 holders in total.
FixWatch the largest wallets that are not exchanges, pools or locks — those are the ones that can move the price.
StatusAcknowledged
Info

Listed, but not independently verified

QA-IDENTITYListed on CoinGecko as Tajir (TJR). 1 holders.
IssueListed on CoinGecko as Tajir (TJR). 1 holders.
FixMatch the contract address against the project's official channels before trading.
StatusAcknowledged
Info

The market for this token

QA-MARKETLiquidity $98K (DexScreener, all pools). 24h trading volume $79K (CoinGecko, all markets, daily snapshot). 24h trading volume $67K (DexScreener, all pools).
IssueLiquidity $98K (DexScreener, all pools). 24h trading volume $79K (CoinGecko, all markets, daily snapshot). 24h trading volume $67K (DexScreener, all pools).
FixSize any position to the liquidity and daily volume shown — they set how much you can sell and at what price.
StatusAcknowledged
Info

Asset class: Project token

QA-PROFILEA token issued by a project for use, governance or fundraising. Scored on its contract and market facts. The class itself adds no points; the contract and market facts decide the score. Basis: no class-specific evidence. Tokenomics — Supply: fixed — the contract has no mint function. Control: an owner that could not be resolved. Code: upgradeable proxy. Fees: no buy or sell tax. Market: $98K of DEX liquidity across 1 pools. Launch: 7 days of market history.
IssueA token issued by a project for use, governance or fundraising. Scored on its contract and market facts. The class itself adds no points; the contract and market facts decide the score. Basis: no class-specific evidence. Tokenomics — Supply: fixed — the contract has no mint function. Control: an owner that could not be resolved. Code: upgradeable proxy. Fees: no buy or sell tax. Market: $98K of DEX liquidity across 1 pools. Launch: 7 days of market history.
FixCheck the project's own documentation for what the token is used for; this report covers what the contract allows.
StatusAcknowledged
Info

Recently launched — 7 days of market history

QA-RECENTThe token's oldest DEX pool is 7 days old. Age is not part of the risk score — a new token is not a risky one by default — but a short history means fewer trades and holder changes behind the facts in this report.
IssueThe token's oldest DEX pool is 7 days old. Age is not part of the risk score — a new token is not a risky one by default — but a short history means fewer trades and holder changes behind the facts in this report.
FixRe-check ownership, liquidity and holder distribution as the token matures; those are the facts that move early.
StatusAcknowledged

Category Ratings

TechnicalLow8/10

The contract implements a standard ERC-20 token with burn functionality, inheriting from OpenZeppelin's `ERC20BurnableUpgradeable`. It uses `AccessControlUpgradeable` for managing administrative roles, such as granting and revoking permissions (7.3 Access Control). The `CODE MAP` indicates no custom logic that directly affects token transfers based on privileged state, ensuring predictable token movement (7.2 Code Security).

GovernanceHigh2/10

Access control is robustly implemented using OpenZeppelin's `AccessControlUpgradeable` pattern (7.3 Access Control). Administrative functions like `grantRole`, `revokeRole`, and `renounceRole` are restricted to specific roles, preventing unauthorized changes to permissions. This centralized control over roles is a strength, though it centralizes power. No specific economic vulnerabilities were identified in the provided code map (7.4 Economic, 7.5 Governance).

UpgradesHigh1/10

The contract utilizes the UUPS (Universal Upgradeable Proxy Standard) pattern, allowing for future upgrades of the implementation logic (7.1 Architecture). The `upgradeToAndCall` function, which performs the upgrade, is protected by an access control role, ensuring only authorized entities can initiate upgrades. While UUPS is a secure and widely adopted pattern, any upgrade introduces a degree of operational risk and requires careful execution (7.7 Upgrades).

Security Checklist

Contract VerifiedPass
Ownership Renounced?
No Mint FunctionPass
Liquidity LockedFail
Not a ProxyFail
HoneypotNoneBuy Tax0.0%Sell Tax0.0%

Proxy Upgrade Controls

Proxy TypeEip1967 Uups
ImplementationVerified source
Upgrades (30d)0 · stable

Holder Composition

0.0% in wallets100.0% in contracts
Effective Concentration40.0%

Share held by contracts — treasury, vesting, bridge or staking — is discounted against share held by wallets when the score is computed: a contract cannot decide to sell the way an anonymous holder can, though it can still be drained or voted to sell. Effective concentration is the figure the risk score is actually calculated from.

Liquidity Depth

The risk score reads depth across every pair. The volume figure and the volume-to-liquidity ratio elsewhere on this page describe only the pair this audit analysed, so the two are not directly comparable.

Key Addresses

Deployer
0xb356…b7c3

What Raised This Score

  • Upgradeable proxy — the admin can replace the logic
  • Ownership status UNKNOWN (owner could not be resolved)
  • Liquidity NOT locked (100% of the pool) — who holds it cannot be verified
  • Top-10 concentration > 30% (100.0% total → 40.0% effective; 0.0% in EOAs, 100.0% in contracts)

Each factor is an on-chain fact recorded at the time of this analysis. The score is computed from them by a deterministic function, so the same contract returns the same score for anyone who runs the audit. How scores are computed

Related Audits

DeXeMedium RiskRadicle (RAD)Medium RiskMantle (MNT)Medium RiskOcean Token (OCEAN)Medium RiskShuffle (SHFL)Medium RiskToken Prometeus Network (PROM)Medium Risk

Would You Like a More Detailed Audit of Tajir?

Our AI-powered scanner gives you a deeper, real-time smart contract analysis — free, with every scoring factor shown.

Get Detailed Audit