Orivon Attila V0.0.1

Web3 Score provider (orivon-web3-score/1). Use this site's address followed by /score as the Web3 Score provider in Orivon's Settings > Web3.

score/provider.json

Websites

Aave

version release-2026-10-05_04-19 · evaluated 2026-10-05

Level 2 of 4Supports DDOC

Aave's official IPFS release of its app, open source. It is not Level 3: when it opens it loads dozens of scripts from app.family.co, Cloudflare's insights beacon and challenge scripts, and sends data to Sentry and Datadog. Markets and balances come from Aave's API and a Tenderly RPC endpoint.

Connections
NameLevelNote
Third-party scripts (app.family.co, Cloudflare insights and challenge)Level 1 of 3Relies on centralized parties; received data cannot be verifiedLoaded when the page opens, without asking.
Error and usage reporting (Sentry, Datadog)Level 1 of 3Relies on centralized parties; received data cannot be verifiedSent when the page opens.
Aave's API (api.v3.aave.com) and RPC (mainnet.gateway.tenderly.co)Level 1 of 3Relies on centralized parties; received data cannot be verifiedMarket data, trusted as given.

Evidence

Aerodrome

evaluated 2026-10-05

Level 2 of 4Supports DDOC

Aerodrome's trading app on Base. No public source was found for the frontend (the project publishes contracts, SDKs and docs), so it stays at Level 2. When it opens it reads chain data from Alchemy and dRPC endpoints and contacts WalletConnect's servers.

Connections
NameLevelNote
RPC endpoints (Alchemy, lb.drpc.live)Level 1 of 3Relies on centralized parties; received data cannot be verifiedRead without a light client.
WalletConnect's servers (pulse.walletconnect.org, api.web3modal.org)Level 1 of 3Relies on centralized parties; received data cannot be verifiedContacted when the page opens, before any wallet is connected.

Evidence

AirGap Vault

version 3.34.4 · evaluated 2026-10-05

Level 4 of 4+ privacyTrustless operations (Level 4) and connections (Level 2), except what the user clearly knows is not trustless; privacy: every activity, including connections and operations, is privacy preserving; no connection shows the user to another party, even with consent

An offline signer, built from upstream's open source at a pinned commit. It runs only its own bundled code and makes no network request: every file it loads comes from its own tree. In Orivon it creates and shows accounts but cannot sign, because QR scanning and clipboard reading are refused to every site. It is designed for a phone kept offline; this computer is not.

Operations
NameLevelNote
Create or import a secretLevel 4 of 5No centralized or untrusted party can act against the user's interestsGenerated from touch, dice, coin flips or a typed mnemonic, and kept in this site's browser storage on this computer. No other party takes part.
Derive and show accountsLevel 4 of 5+ privacyNo centralized or untrusted party can act against the user's interests; privacy: reasonably untrackable and indecipherable without user consentComputed on this computer, WebAssembly included, with nothing sent anywhere.

Evidence

AirSwap

evaluated 2026-10-05

Level 2 of 4Supports DDOC

AirSwap's web app, open source (MIT). It is not Level 3: when it opens it loads Google Tag Manager and Google Analytics, and fonts from Adobe Typekit. Trades settle on chain, but the app reads through hosted endpoints and makers' own servers.

Connections
NameLevelNote
Google Tag Manager and Google AnalyticsLevel 1 of 3Relies on centralized parties; received data cannot be verifiedLoaded when the page opens, without asking.
Adobe Typekit fonts (use.typekit.net)Level 1 of 3Relies on centralized parties; received data cannot be verifiedFetched when the page opens; tells Adobe the visit.

Evidence

Alcove

evaluated 2026-10-05

Level 3 of 4Open source; runs no external code without the user's willing, aware consent

Alcove, an RSS reader, open source (MIT). It runs no third-party code, which is Level 3. It is not Level 4: when it opens it connects to its author's sync relays (relay.alcove.tools), and feeds are fetched through its author's proxies (proxy.alcove.tools), which see what you read.

Connections
NameLevelNote
Sync relays (wss://relay.alcove.tools, wss://relay2.alcove.tools)Level 1 of 3Relies on centralized parties; received data cannot be verifiedConnected when the page opens.
Feed proxies (proxy.alcove.tools, proxy2.alcove.tools)Level 1 of 3Relies on centralized parties; received data cannot be verifiedEvery feed is fetched through them.

Evidence

API3 DAO

evaluated 2026-10-05

Level 2 of 4Supports DDOC

The API3 DAO staking and voting dashboard. Its source is public (no licence file). It is not Level 3: when it opens, its wallet library loads WalletConnect's hidden verify frame, third-party code the user has not asked for. It also embeds a YouTube video and loads Google Fonts.

Connections
NameLevelNote
WalletConnect verify frame and wallet listLevel 1 of 3Relies on centralized parties; received data cannot be verifiedLoaded when the page opens, before any wallet is connected.
YouTube embed (youtube-nocookie.com)Level 1 of 3Relies on centralized parties; received data cannot be verifiedA visible player on the page.
Google FontsLevel 1 of 3Relies on centralized parties; received data cannot be verifiedFetched when the page opens; tells Google the visit.

Evidence

ASGARDEX

version 1.45.3 · evaluated 2026-10-05

Level 3 of 4Open source; runs no external code without the user's willing, aware consent

A THORChain and MAYAChain wallet and exchange. Its code is open source and every script it runs ships in its own bundle, which is Level 3. It is not Level 4: balances, quotes and vault addresses come from centralised APIs that are not checked against any chain.

Operations
NameLevelNote
Create or unlock the keystore walletLevel 4 of 5+ privacyNo centralized or untrusted party can act against the user's interests; privacy: reasonably untrackable and indecipherable without user consentThe seed is generated and encrypted on this computer, and no other party takes part.
Send BTC, ETH and other native assetsLevel 3 of 5Relies only on network contexts considered trustless enoughSigned on this computer and settled by each chain. Balances, unspent outputs and fee rates come from centralised APIs, which can mislead or refuse but cannot redirect the funds.
Swap through THORChain or MAYAChainLevel 2 of 5Source code available, and verifiably does what it promisesThe code does what it promises, but the vault address and the quote are read from a centralised API, so a lying endpoint could send funds astray. Node operators can also halt trading by vote.
Add or withdraw liquidityLevel 2 of 5Source code available, and verifiably does what it promisesThe same exposure as a swap: vault addresses and pool data come from a centralised API.
Connections
NameLevelNote
THORChain and MAYAChain APIs (Midgard, THORNode, MAYANode)Level 1 of 3Relies on centralized parties; received data cannot be verifiedPublic endpoints run by a few operators. Answers are not proven against either chain.
Blockchain data providers (Blockcypher, Haskoin, Etherscan, Blockfrost)Level 1 of 3Relies on centralized parties; received data cannot be verifiedBalances and history from centralised indexers, unchecked. Each learns the addresses you hold.
EVM JSON-RPC endpoints (publicnode, 1rpc, BNB Chain, Arbitrum, Avalanche)Level 1 of 3Relies on centralized parties; received data cannot be verifiedRead without a light client, so every answer is trusted as given.
Price data (CoinGecko)Level 1 of 3Relies on centralized parties; received data cannot be verifiedOne centralised source. It changes displayed values only.

Evidence

Austin Vernon's blog

evaluated 2026-10-05

Level 3 of 4Open source; runs no external code without the user's willing, aware consent

Austin Vernon's blog: plain HTML served as written, so its source is public, and it runs no script, which is Level 3. It is not Level 4: when it opens it loads images from Imgur.

Connections
NameLevelNote
Imgur (i.imgur.com)Level 1 of 3Relies on centralized parties; received data cannot be verifiedImages fetched when the page opens.

Evidence

Banny's Network

evaluated 2026-10-05

Level 3 of 4Open source; runs no external code without the user's willing, aware consent

Banny's Network, a page built with Planet's Croptop template, whose source is public (no licence file). It runs no third-party code, which is Level 3. It is not Level 4: when it opens it asks pinnable.xyz for the peers of its IPNS name.

Connections
NameLevelNote
Pinnable API (www.pinnable.xyz)Level 1 of 3Relies on centralized parties; received data cannot be verifiedContacted when the page opens.

Evidence

CoW Swap

evaluated 2026-10-05

Level 2 of 4Supports DDOC

CoW Swap's trading app, open source (GPL-3.0). It is not Level 3: when it opens it loads third-party code nobody is told about: Google Tag Manager, Microsoft Clarity session replay, Reddit, X and Adform ad pixels, Sentry error reporting and LaunchDarkly feature flags. Quotes, orders and balances come from CoW Protocol's own servers and an Infura endpoint.

Connections
NameLevelNote
Analytics, session replay and ad pixels (Google, Clarity, Reddit, X, Adform)Level 1 of 3Relies on centralized parties; received data cannot be verifiedLoaded when the page opens, without asking.
Error reporting and feature flags (Sentry, LaunchDarkly)Level 1 of 3Relies on centralized parties; received data cannot be verifiedLoaded when the page opens, without asking.
CoW Protocol APIs (api.cow.fi, bff.barn.cow.fi, cms.cow.fi)Level 1 of 3Relies on centralized parties; received data cannot be verifiedQuotes, orders and token data from the team's servers, trusted as given.
Ethereum RPC (mainnet.infura.io)Level 1 of 3Relies on centralized parties; received data cannot be verifiedRead without a light client.

Evidence

Croptop

evaluated 2026-10-05

Level 2 of 4Supports DDOC

Croptop's site, a page built with Planet's Croptop template, whose source is public (no licence file). It is not Level 3: when it opens it loads Plausible's analytics script. It also reads from juicebox.center.

Connections
NameLevelNote
Plausible analytics (plausible.io)Level 1 of 3Relies on centralized parties; received data cannot be verifiedLoaded when the page opens, without asking.
Juicebox data (juicebox.center)Level 1 of 3Relies on centralized parties; received data cannot be verifiedOne centralised source.

Evidence

Dapp Rank

evaluated 2026-10-05

Level 3 of 4Open source; runs no external code without the user's willing, aware consent

Dapp Rank, which rates dapps on censorship resistance, open source (GPL-3.0). It runs no third-party code, which is Level 3. It is not Level 4: when it opens, its own code reports the visit to Plausible.

Connections
NameLevelNote
Plausible (plausible.io/api/event)Level 1 of 3Relies on centralized parties; received data cannot be verifiedVisit reported by the page's own code when it opens.

Evidence

Devcon

evaluated 2026-10-05

Level 3 of 4Open source; runs no external code without the user's willing, aware consent

Devcon's link page at devcon.eth, open source (GPL-3.0). It runs no third-party code, which is Level 3. It is not Level 4: when it opens it reads links from devcon.org's API, images from Supabase and records from a public RPC endpoint.

Connections
NameLevelNote
Devcon's API (devcon.org) and SupabaseLevel 1 of 3Relies on centralized parties; received data cannot be verifiedContent from servers the team runs, read when the page opens.
RPC endpoint (ethereum-rpc.publicnode.com) and euc.liLevel 1 of 3Relies on centralized parties; received data cannot be verifiedRead without a light client.

Evidence

DXdao

evaluated 2026-10-05

Level 2 of 4Supports DDOC

DXdao's website and contributor hub. No public source was found for this site (a Gatsby build; DXdao's public repositories hold its other products), so it stays at Level 2. When it opens it reads figures from DefiLlama's API.

Connections
NameLevelNote
DefiLlama API (api.llama.fi)Level 1 of 3Relies on centralized parties; received data cannot be verifiedOne centralised source, read when the page opens.

Ethereum File System

evaluated 2026-10-05

Level 3 of 4Open source; runs no external code without the user's willing, aware consent

The Ethereum File System app, open source (MIT). It runs no third-party code, which is Level 3. It is not Level 4: when it opens it reads chain data from Alchemy and dRPC endpoints, sends WalletConnect telemetry and loads Google Fonts.

Connections
NameLevelNote
RPC endpoints (Alchemy, sepolia.drpc.org)Level 1 of 3Relies on centralized parties; received data cannot be verifiedRead without a light client.
WalletConnect's servers (pulse, explorer-api.walletconnect.com)Level 1 of 3Relies on centralized parties; received data cannot be verifiedContacted when the page opens.
Google FontsLevel 1 of 3Relies on centralized parties; received data cannot be verifiedFetched when the page opens; tells Google the visit.

Evidence

Element

version 1.12.29 · evaluated 2026-10-05

Level 4 of 4Trustless operations (Level 4) and connections (Level 2), except what the user clearly knows is not trustless

A Matrix chat client, built from upstream's open source at a pinned commit. Third-party code (widgets, the integration manager, calls) loads only in frames the person opens or accepts. The homeserver the user signs in to holds the account and delivers every message, which a user clearly knows; encryption keys stay on this computer, and the other services are used only on the user's action or consent. That is Level 4 under the exception for evident trust. Not private: servers see who talks to whom and when.

Operations
NameLevelNote
Send and receive messagesLevel 2 of 5Source code available, and verifiably does what it promisesThe code does what it promises. In encrypted rooms the servers cannot read or forge messages, but they see who talks to whom and when, and can withhold delivery.
Your accountLevel 2 of 5Source code available, and verifiably does what it promisesHeld by the homeserver you sign in to (matrix.org unless you choose another), which can suspend or remove it.
Keep encryption keys and historyLevel 4 of 5No centralized or untrusted party can act against the user's interestsStored in this site's browser storage on this computer. The key that protects them sits in the same storage, not in the system keyring.
Connections
NameLevelNote
Matrix homeserver (matrix.org by default)Level 1 of 3Relies on centralized parties; received data cannot be verifiedRooms, members and history come from the homeserver, which the client trusts as given. It also sees your IP address.
Identity server (vector.im)Level 1 of 3Relies on centralized parties; received data cannot be verifiedUsed when you look someone up by email or phone number.
Integrations and widgets (scalar.vector.im)Level 1 of 3Relies on centralized parties; received data cannot be verifiedThird-party services, loaded when you open the integration manager or accept a widget.
Usage analytics (posthog.element.io)Level 1 of 3Relies on centralized parties; received data cannot be verifiedOff unless you agree to share it when asked.
Location maps (api.maptiler.com)Level 1 of 3Relies on centralized parties; received data cannot be verifiedMap tiles, fetched when you share or view a location.
Bug reports (rageshakes.element.io)Level 1 of 3Relies on centralized parties; received data cannot be verifiedSent only when you submit one, with the logs you choose to include.

Evidence

ENS documentation

evaluated 2026-10-05

Level 2 of 4Supports DDOC

The ENS documentation, open source (CC0). It is not Level 3: when it opens it loads a documentation chatbot script from jsDelivr (@cookbookdev/docsbot) with no integrity hash, third-party code the user has not asked for. It also fetches the Solidity compiler list and loads Google Fonts.

Connections
NameLevelNote
Docs chatbot script (cdn.jsdelivr.net, playgr.app)Level 1 of 3Relies on centralized parties; received data cannot be verifiedLoaded when the page opens, without an integrity hash.
Google Fonts and binaries.soliditylang.orgLevel 1 of 3Relies on centralized parties; received data cannot be verifiedFetched when the page opens.

Evidence

ENS

evaluated 2026-10-05

Level 2 of 4Supports DDOC

The ENS manager app, open source (MIT). It is not Level 3: when it opens it loads Plausible's analytics script, Intercom's chat widget and WalletConnect's hidden verify frame. Names are read from the ENS subgraph and RPC endpoints.

Connections
NameLevelNote
Plausible analytics and Intercom chat widgetLevel 1 of 3Relies on centralized parties; received data cannot be verifiedLoaded when the page opens, without asking.
WalletConnect verify frame (verify.walletconnect.com)Level 1 of 3Relies on centralized parties; received data cannot be verifiedLoaded when the page opens, before any wallet is connected.

Evidence

ENS Interviews

evaluated 2026-10-05

Level 4 of 4+ privacyTrustless operations (Level 4) and connections (Level 2), except what the user clearly knows is not trustless; privacy: every activity, including connections and operations, is privacy preserving; no connection shows the user to another party, even with consent

ENS Interviews, a static site built with Spheron's site builder. It serves its scripts with their source maps, so their source is readable in what it serves, and it loads only its own files, so it makes no request beyond the site itself.

Evidence

Eternal Safe

evaluated 2026-10-05

Level 3 of 4Open source; runs no external code without the user's willing, aware consent

Eternal Safe, a decentralised fork of the Safe{Wallet} interface, open source (GPL-3.0). It makes no request when it opens and runs no third-party code, which is Level 3. It is not Level 4: once a network is chosen, Safe accounts are read through public RPC endpoints (Infura, Ankr and others) by default, without a light client. A custom endpoint can be set.

Connections
NameLevelNote
Public RPC endpoints (Infura, Ankr, Gateway.fm and others)Level 1 of 3Relies on centralized parties; received data cannot be verifiedUsed once a network is chosen, without a light client.

Evidence

Ethereum Phunks Market

evaluated 2026-10-05

Level 2 of 4Supports DDOC

The Ethereum Phunks marketplace, open source (CC0). It is not Level 3: when it opens it loads Plausible's analytics script. Listings come from the team's relay, a Supabase database and other indexers, and chain data from Alchemy.

Connections
NameLevelNote
Plausible analytics (plausible.io)Level 1 of 3Relies on centralized parties; received data cannot be verifiedLoaded when the page opens, without asking.
Team-run services (relay.ethereumphunks.com, Supabase, floored.app)Level 1 of 3Relies on centralized parties; received data cannot be verifiedListings and sales from servers the team runs, trusted as given.
RPC endpoint (eth-mainnet.g.alchemy.com)Level 1 of 3Relies on centralized parties; received data cannot be verifiedRead without a light client.

Evidence

EthHub

evaluated 2026-10-05

Level 2 of 4Supports DDOC

An old build of EthHub's community documentation, whose content is public (CC BY-SA 4.0). It is not Level 3: when it opens it loads Google Tag Manager and Google Analytics.

Connections
NameLevelNote
Google Tag Manager and Google AnalyticsLevel 1 of 3Relies on centralized parties; received data cannot be verifiedLoaded when the page opens, without asking.
Google FontsLevel 1 of 3Relies on centralized parties; received data cannot be verifiedFetched when the page opens; tells Google the visit.

Evidence

ETHMumbai

evaluated 2026-10-05

Level 2 of 4Supports DDOC

ETHMumbai's page for its March 2026 event. No public source matches this build, so it stays at Level 2. When it opens it loads Google Fonts and calls www.ethmumbai.in.

Connections
NameLevelNote
Google Fonts and www.ethmumbai.inLevel 1 of 3Relies on centralized parties; received data cannot be verifiedFetched when the page opens.

Orivon Explore

version 0.1.0 · evaluated 2026-10-05

Level 4 of 4Trustless operations (Level 4) and connections (Level 2), except what the user clearly knows is not trustless

Orivon's directory of Web3 sites, open source, and judged here by its own publisher. The page sends no request itself: the directory and a dated snapshot of judgements ship inside it. It is not private: a visitor who grants trust.score has Orivon resolve every listed .eth name and ask their Web3 Score provider about every listed site, which shows the provider their IP address and that they opened Explore. Which sites it lists is the publisher's choice, fixed in each build.

Operations
NameLevelNote
Browse and filter the directoryLevel 4 of 5+ privacyNo centralized or untrusted party can act against the user's interests; privacy: reasonably untrackable and indecipherable without user consentRuns entirely on this computer. Nothing is sent while you browse.

Evidence

Fileverse Walkaway

evaluated 2026-10-05

Level 3 of 4Open source; runs no external code without the user's willing, aware consent

Fileverse Walkaway, which recovers dDocs and dSheets when Fileverse's own apps are offline, open source (AGPL-3.0). It makes no request when it opens and runs no third-party code, which is Level 3. It is not Level 4: recovering documents reads the chain through public RPC endpoints (Gnosis Chain, Alchemy) and files through IPFS gateways.

Connections
NameLevelNote
RPC endpoints (rpc.gnosischain.com, Alchemy)Level 1 of 3Relies on centralized parties; received data cannot be verifiedUsed during recovery, without a light client.
IPFS gateways (gateway.ipfs.io, ipfs.io)Level 1 of 3Relies on centralized parties; received data cannot be verifiedUsed during recovery.

Evidence

FOCIL

evaluated 2026-10-05

Level 2 of 4Supports DDOC

An explainer for FOCIL (fork-choice enforced inclusion lists), open source (MIT). It is not Level 3: when it opens it loads MathJax from jsDelivr with no integrity hash and a floating version, code the CDN can change at any time. Its Bootstrap and Popper scripts are pinned by integrity hashes, which is fine.

Connections
NameLevelNote
MathJax (cdn.jsdelivr.net)Level 1 of 3Relies on centralized parties; received data cannot be verifiedA script loaded when the page opens, without an integrity hash.
Bootstrap, Popper, Font Awesome and Google Fonts from CDNsLevel 1 of 3Relies on centralized parties; received data cannot be verifiedFetched when the page opens.

Evidence

FreeTube

version 0.25.3 · evaluated 2026-10-05

Level 4 of 4Trustless operations (Level 4) and connections (Level 2), except what the user clearly knows is not trustless

A YouTube client without ads or an account, built from upstream's open source at a pinned commit. To play a video it runs YouTube's own code: the player's signature functions in a sandboxed frame, and Google's BotGuard in a youtube.com context. The user knows this from Orivon's grant dialog, and using YouTube is why they open the app. Videos and comments come from YouTube or an Invidious instance, which a user clearly knows are run by someone; subscriptions and history stay on this computer. Level 4 under the exception for evident trust. Not private: YouTube sees what you watch.

Operations
NameLevelNote
Watch, search and read commentsLevel 2 of 5Source code available, and verifiably does what it promisesThe code does what it promises, but YouTube or the chosen Invidious instance decides what is served, and sees your IP address and what you watch.
Keep subscriptions, history and playlistsLevel 4 of 5+ privacyNo centralized or untrusted party can act against the user's interests; privacy: reasonably untrackable and indecipherable without user consentStored only in this app's own files on this computer, with no account.
Refresh the subscription feedLevel 2 of 5Source code available, and verifiably does what it promisesEach subscribed channel is fetched from YouTube or Invidious, which can link the list to your IP address.
Connections
NameLevelNote
YouTube (youtubei.googleapis.com, www.youtube.com, image hosts)Level 1 of 3Relies on centralized parties; received data cannot be verifiedGoogle's servers. Answers cannot be checked against anything else.
Invidious instancesLevel 1 of 3Relies on centralized parties; received data cannot be verifiedIndependent proxies of YouTube, used when chosen or as a fallback. Each sees your requests.
SponsorBlock (sponsor.ajay.app)Level 1 of 3Relies on centralized parties; received data cannot be verifiedCrowd-sourced segment data, when turned on. Asked by a hash prefix of the video id.
Return YouTube DislikeLevel 1 of 3Relies on centralized parties; received data cannot be verifiedEstimated dislike counts from one service, when turned on.

Evidence

Gnosis VPN documentation

evaluated 2026-10-05

Level 3 of 4Open source; runs no external code without the user's willing, aware consent

The Gnosis VPN documentation. Its source is public (no licence file) and it runs no third-party code, which is Level 3. It is not Level 4: when it opens it loads an icon font from jsDelivr.

Connections
NameLevelNote
Tabler icon font (cdn.jsdelivr.net)Level 1 of 3Relies on centralized parties; received data cannot be verifiedFetched when the page opens.

Evidence

Greg Skriloff

evaluated 2026-10-05

Level 3 of 4Open source; runs no external code without the user's willing, aware consent

Greg Skriloff's profile card: one hand-written page served as written, so its source is public, and it runs no third-party code, which is Level 3. It is not Level 4: when it opens it loads the profile picture from GitHub's avatar server.

Connections
NameLevelNote
GitHub avatars (avatars.githubusercontent.com)Level 1 of 3Relies on centralized parties; received data cannot be verifiedImage fetched when the page opens.

Evidence

Hop

evaluated 2026-10-05

Level 2 of 4Supports DDOC

Hop's bridge app, open source (MIT). It is not Level 3: when it opens it loads Google Tag Manager and Google Analytics. Chain state comes from public RPC endpoints (Ankr, 1RPC) and bridge data from Hop's subgraph, unchecked. hop.eth points to a DNSLink record on app.hop.exchange, so what the name serves follows whoever controls that domain's DNS.

Connections
NameLevelNote
Google Tag Manager and Google AnalyticsLevel 1 of 3Relies on centralized parties; received data cannot be verifiedLoaded when the page opens, without asking.
Public RPC endpoints (rpc.ankr.com, 1rpc.io)Level 1 of 3Relies on centralized parties; received data cannot be verifiedRead without a light client.
Google FontsLevel 1 of 3Relies on centralized parties; received data cannot be verifiedFetched when the page opens; tells Google the visit.

Evidence

Immutable Frontends

evaluated 2026-10-05

Level 2 of 4Supports DDOC

Immutable Frontends, a registry of verified decentralised frontends. Its source is public (no licence file). It is not Level 3: when it opens it loads a script from cdn.gpteng.co, the Lovable site builder's, which the user is not told about. Its registry data comes from The Graph's gateway.

Connections
NameLevelNote
Lovable script (cdn.gpteng.co)Level 1 of 3Relies on centralized parties; received data cannot be verifiedLoaded when the page opens, without asking.
The Graph's gateway (gateway.thegraph.com)Level 1 of 3Relies on centralized parties; received data cannot be verifiedRegistry data, read without proof.
Google FontsLevel 1 of 3Relies on centralized parties; received data cannot be verifiedFetched when the page opens; tells Google the visit.

Evidence

IPFS blog

evaluated 2026-10-05

Level 3 of 4Open source; runs no external code without the user's willing, aware consent

A build of the IPFS blog, open source (MIT). Its home page runs no third-party code and makes no request beyond its own files, which is Level 3. It is not judged Level 4: many of its files, posts and sitemap included, could not be fetched from IPFS on 2026-10-05, so what they load could not be checked.

Evidence

IPFS documentation

evaluated 2026-10-05

Level 2 of 4Supports DDOC

A build of the IPFS documentation, open source (MIT for code). It is not Level 3: when it opens it loads Google Analytics and SpeedCurve's performance monitoring script.

Connections
NameLevelNote
Google Analytics and SpeedCurve (cdn.speedcurve.com)Level 1 of 3Relies on centralized parties; received data cannot be verifiedLoaded when the page opens, without asking.

Evidence

IPFS

evaluated 2026-10-05

Level 2 of 4Supports DDOC

An old build of the ipfs.io website, from the archived open-source repository (MIT); the IPFS project's current site is ipfs.tech. It is not Level 3: when it opens it loads Google Analytics and a script from camp.ipfs.io.

Connections
NameLevelNote
Google Analytics and camp.ipfs.io scriptLevel 1 of 3Relies on centralized parties; received data cannot be verifiedLoaded when the page opens, without asking.

Evidence

IPLD

evaluated 2026-10-05

Level 2 of 4Supports DDOC

The IPLD website, open source (Apache-2.0 or MIT). It is not Level 3: a YouTube player embedded in the page loads Google's code as soon as the page opens, before the reader chooses to play anything. It also loads Google Fonts.

Connections
NameLevelNote
YouTube embed (www.youtube.com)Level 1 of 3Relies on centralized parties; received data cannot be verifiedA visible player on the page, loaded when it opens.
Google FontsLevel 1 of 3Relies on centralized parties; received data cannot be verifiedFetched when the page opens; tells Google the visit.

Evidence

James Carnley

evaluated 2026-10-05

Level 4 of 4Trustless operations (Level 4) and connections (Level 2), except what the user clearly knows is not trustless

James Carnley's homepage, open source (MIT). It loads only its own files. Its videos are the one connection elsewhere, and the page says so: pressing play loads the video from YouTube, and until then nothing on the page talks to Google. That keeps it Level 4. It is not private: once a video plays, YouTube sees the reader's IP address, with no proxy in between.

Connections
NameLevelNote
YouTube videosLevel 1 of 3Relies on centralized parties; received data cannot be verifiedLoaded only when the reader presses play, which the page explains beside each video.

Evidence

JSONAPI.ETH

evaluated 2026-10-05

Level 3 of 4Open source; runs no external code without the user's willing, aware consent

The page of JSONAPI.ETH, an ENS resolver that answers onchain queries as JSON. Its source is public (no licence file) and it runs no third-party code, which is Level 3. It is not Level 4: a query runs through an RPC endpoint and the resolver's off-chain gateway, run by its authors, whose answers the page does not check.

Connections
NameLevelNote
RPC endpoint and the resolver's gatewayLevel 1 of 3Relies on centralized parties; received data cannot be verifiedUsed when a query is submitted.

Evidence

Mandalas

evaluated 2026-10-05

Level 3 of 4Open source; runs no external code without the user's willing, aware consent

Mandalas, onchain generative NFTs, open source (AGPL-3.0). It runs no third-party code, which is Level 3. It is not Level 4: when it opens it reads the chain through ethereum.etherplay.io, an RPC endpoint run by the author, without a light client.

Connections
NameLevelNote
RPC endpoint (ethereum.etherplay.io)Level 1 of 3Relies on centralized parties; received data cannot be verifiedRead without a light client.

Evidence

OpenScan

evaluated 2026-10-05

Level 3 of 4Open source; runs no external code without the user's willing, aware consent

OpenScan, a block explorer for Bitcoin and EVM networks, open source (MIT). It runs no third-party code, which is Level 3. It is not Level 4: when it opens it queries dozens of public RPC endpoints and Bitcoin APIs, contacts WalletConnect and loads Google Fonts. The endpoints can be changed in its settings, but the defaults are not checked against the chain.

Connections
NameLevelNote
Public RPC endpoints and Bitcoin APIs (drpc, publicnode, mempool.space, others)Level 1 of 3Relies on centralized parties; received data cannot be verifiedQueried when the page opens, without a light client.
RPC list (cdn.jsdelivr.net) and OpenScan's proxy (openscan.workers.dev)Level 1 of 3Relies on centralized parties; received data cannot be verifiedFetched when the page opens.
WalletConnect's servers and Google FontsLevel 1 of 3Relies on centralized parties; received data cannot be verifiedContacted when the page opens.

Evidence

PinMe

evaluated 2026-10-05

Level 2 of 4Supports DDOC

PinMe's website. Its public repository is the PinMe command-line tool, not this site, which is a minified bundle with no public source, so it stays at Level 2. When it opens it calls PinMe's servers and GitHub's API, and loads Google Fonts.

Connections
NameLevelNote
PinMe's servers (pinme.dev, pindata.dev) and GitHub's APILevel 1 of 3Relies on centralized parties; received data cannot be verifiedContacted when the page opens.
Google FontsLevel 1 of 3Relies on centralized parties; received data cannot be verifiedFetched when the page opens; tells Google the visit.

Evidence

Planet

evaluated 2026-10-05

Level 2 of 4Supports DDOC

A Planet-generated site published at planetable.eth, built with Planet's Plain template, whose source is public (no licence file). It is not Level 3: when it opens it loads Plausible's analytics script.

Connections
NameLevelNote
Plausible analytics (plausible.io)Level 1 of 3Relies on centralized parties; received data cannot be verifiedLoaded when the page opens, without asking.

Evidence

Project DAVI

evaluated 2026-10-05

Level 3 of 4Open source; runs no external code without the user's willing, aware consent

Project DAVI's landing page. Its source is public (no licence file) and it runs no third-party code, which is Level 3. It is not Level 4: when it opens it loads Bootstrap's stylesheet from jsDelivr and Google Fonts.

Connections
NameLevelNote
Bootstrap stylesheet (cdn.jsdelivr.net) and Google FontsLevel 1 of 3Relies on centralized parties; received data cannot be verifiedFetched when the page opens.

Evidence

Raffy

evaluated 2026-10-05

Level 4 of 4+ privacyTrustless operations (Level 4) and connections (Level 2), except what the user clearly knows is not trustless; privacy: every activity, including connections and operations, is privacy preserving; no connection shows the user to another party, even with consent

Raffy's personal page: hand-written HTML served as written, so its source is public. It loads only its own files (its pictures included) and runs no script, so it makes no request beyond the site itself.

Evidence

Reality.eth

evaluated 2026-10-05

Level 3 of 4Open source; runs no external code without the user's willing, aware consent

Reality.eth, the crowd-sourced oracle's app, open source (GPL-3.0). It runs no third-party code, which is Level 3. It is not Level 4: when it opens it reads the question list from an indexer, indexer.reality.gwei.name, without proof.

Connections
NameLevelNote
Indexer (indexer.reality.gwei.name)Level 1 of 3Relies on centralized parties; received data cannot be verifiedQuestion lists, read when the page opens, without proof.

Evidence

Rekt

evaluated 2026-10-05

Level 2 of 4Supports DDOC

Rekt News. No public source was found for this site, and when it opens it loads Google Tag Manager, so it stays at Level 2.

Connections
NameLevelNote
Google Tag Manager and Google AnalyticsLevel 1 of 3Relies on centralized parties; received data cannot be verifiedLoaded when the page opens, without asking.
Google Fonts and images from raw.githubusercontent.comLevel 1 of 3Relies on centralized parties; received data cannot be verifiedFetched when the page opens.

Remix IDE

evaluated 2026-10-05

Level 2 of 4Supports DDOC

Remix IDE, open source (Apache-2.0). It is not Level 3: when it opens it loads Font Awesome's kit script from kit.fontawesome.com, third-party code with no integrity hash that the provider can change at any time. It also embeds an X timeline, and fetches compiler lists and plugin data from several hosts.

Connections
NameLevelNote
Font Awesome kit (kit.fontawesome.com)Level 1 of 3Relies on centralized parties; received data cannot be verifiedA script loaded when the page opens, without an integrity hash.
X timeline embed (platform.twitter.com)Level 1 of 3Relies on centralized parties; received data cannot be verifiedA visible embed on the home tab.
Solidity compilers (binaries.soliditylang.org)Level 1 of 3Relies on centralized parties; received data cannot be verifiedCompiler list fetched when the page opens; a compiler is downloaded when one is used.
Plugin and news hosts (raw.githubusercontent.com, rss.remixproject.org)Level 1 of 3Relies on centralized parties; received data cannot be verifiedFetched when the page opens.

Evidence

Resupply

evaluated 2026-10-05

Level 2 of 4Supports DDOC

Resupply's stablecoin app. No public source was found for this frontend: the project's public repository holds its smart contracts only, so it stays at Level 2. What it reaches after a wallet connects was not checked.

Evidence

Revnet

evaluated 2026-10-05

Level 2 of 4Supports DDOC

Revnet's site, a page built with Planet's Croptop template, whose source is public (no licence file). It is not Level 3: when it opens it loads Plausible's analytics script. It also reads from public RPC endpoints and a testnet indexer.

Connections
NameLevelNote
Plausible analytics (plausible.io)Level 1 of 3Relies on centralized parties; received data cannot be verifiedLoaded when the page opens, without asking.
RPC endpoints (eth.llamarpc.com, ethereum-sepolia-rpc.publicnode.com)Level 1 of 3Relies on centralized parties; received data cannot be verifiedRead without a light client.
Indexer (testnet.bendystraw.xyz)Level 1 of 3Relies on centralized parties; received data cannot be verifiedOne centralised source.

Evidence

RicMoo

evaluated 2026-10-05

Level 4 of 4+ privacyTrustless operations (Level 4) and connections (Level 2), except what the user clearly knows is not trustless; privacy: every activity, including connections and operations, is privacy preserving; no connection shows the user to another party, even with consent

Pac-Txt, a Pac-Man and Zork mash-up by RicMoo: one self-contained page served as written, so its source is readable in what it serves (an in-file notice licenses it CC BY-NC 3.0). It runs only its own code and makes no network request, opened or played.

Operations
NameLevelNote
Play the gameLevel 4 of 5+ privacyNo centralized or untrusted party can act against the user's interests; privacy: reasonably untrackable and indecipherable without user consentRuns entirely on this computer.

Evidence

Rocket Sweep

evaluated 2026-10-05

Level 2 of 4Supports DDOC

Rocket Sweep, a tool for Rocket Pool node operators, open source (MIT). It is not Level 3: when it opens, its wallet library loads WalletConnect's hidden verify frame, third-party code the user has not asked for. Chain data comes from an Alchemy key built into the bundle and Cloudflare's Ethereum endpoint.

Connections
NameLevelNote
WalletConnect verify frame and wallet listLevel 1 of 3Relies on centralized parties; received data cannot be verifiedLoaded when the page opens, before any wallet is connected.
RPC endpoints (eth-mainnet.alchemyapi.io, cloudflare-eth.com)Level 1 of 3Relies on centralized parties; received data cannot be verifiedRead without a light client.

Evidence

Ronan Sandford

evaluated 2026-10-05

Level 4 of 4+ privacyTrustless operations (Level 4) and connections (Level 2), except what the user clearly knows is not trustless; privacy: every activity, including connections and operations, is privacy preserving; no connection shows the user to another party, even with consent

Ronan Sandford's personal site. Its source is public (no licence file) and it loads only its own files, on every page, so it makes no request beyond the site itself.

Evidence

Safe

version web-v1.99.2 · evaluated 2026-10-05

Level 2 of 4Supports DDOC

Safe{Wallet}'s official IPFS build, open source. It is not Level 3: when it opens it loads Google Tag Manager and Google Analytics. Accounts and transactions are read from Safe's client gateway (safe-client.safe.global), a server Safe runs.

Connections
NameLevelNote
Google Tag Manager and Google AnalyticsLevel 1 of 3Relies on centralized parties; received data cannot be verifiedLoaded when the page opens, without asking.
Safe's client gateway (safe-client.safe.global)Level 1 of 3Relies on centralized parties; received data cannot be verifiedAccounts, balances and queued transactions, trusted as given.
WalletConnect's servers (pulse.walletconnect.org)Level 1 of 3Relies on centralized parties; received data cannot be verifiedContacted when the page opens.

Evidence

Seedit

evaluated 2026-10-05

Level 3 of 4Open source; runs no external code without the user's willing, aware consent

Seedit, a peer-to-peer alternative to Reddit on the Plebbit protocol, open source (GPL-3.0). It runs no third-party code, which is Level 3. It is not Level 4: when it opens it reads its default community list from raw.githubusercontent.com, a file GitHub serves and nothing checks.

Connections
NameLevelNote
Default community list (raw.githubusercontent.com)Level 1 of 3Relies on centralized parties; received data cannot be verifiedFetched when the page opens.

Evidence

Simple Page

evaluated 2026-10-05

Level 3 of 4Open source; runs no external code without the user's willing, aware consent

Simple Page, a tool to publish a Markdown site at an ENS name, open source (GPL-3.0). It runs no third-party code, which is Level 3. It is not Level 4: when it opens, its own code reports the visit to Plausible and reads from a Tenderly RPC endpoint and the project's servers.

Connections
NameLevelNote
Plausible (plausible.io/api/event)Level 1 of 3Relies on centralized parties; received data cannot be verifiedVisit reported by the page's own code when it opens.
RPC and services (mainnet.gateway.tenderly.co, simplepg.org, euc.li)Level 1 of 3Relies on centralized parties; received data cannot be verifiedRead when the page opens, without proof.

Evidence

SmokeSignal

evaluated 2026-10-05

Level 2 of 4Supports DDOC

SmokeSignal, a forum whose posts are Ethereum transactions. Its source is public (no licence file). It is not Level 3: when it opens it loads Google Tag Manager and Facebook's tracking script. Posts are read from Infura and a Gnosis Chain RPC endpoint.

Connections
NameLevelNote
Google Tag Manager and Facebook pixelLevel 1 of 3Relies on centralized parties; received data cannot be verifiedLoaded when the page opens, without asking.
RPC endpoints (mainnet.infura.io, rpc.gnosischain.com)Level 1 of 3Relies on centralized parties; received data cannot be verifiedRead without a light client.

Evidence

Stackly

evaluated 2026-10-05

Level 2 of 4Supports DDOC

Stackly's recurring-purchase app on CoW Protocol. Its source is public (no licence file). It is not Level 3: when it opens it loads Fathom's analytics script. Token lists come from CoinGecko and chain data from a public RPC endpoint.

Connections
NameLevelNote
Fathom analytics (cdn.usefathom.com)Level 1 of 3Relies on centralized parties; received data cannot be verifiedLoaded when the page opens, without asking.
Token list (tokens.coingecko.com)Level 1 of 3Relies on centralized parties; received data cannot be verifiedOne centralised source.
Public RPC endpoint (arbitrum-one-rpc.publicnode.com)Level 1 of 3Relies on centralized parties; received data cannot be verifiedRead without a light client.

Evidence

Steve Simkins

evaluated 2026-10-05

Level 2 of 4Supports DDOC

Steve Simkins' personal site, open source (MIT). It is not Level 3: when it opens it loads Umami's analytics script. It also fetches icons from the Iconify API.

Connections
NameLevelNote
Umami analytics (cloud.umami.is)Level 1 of 3Relies on centralized parties; received data cannot be verifiedLoaded when the page opens, without asking.
Iconify API and files.stevedylan.devLevel 1 of 3Relies on centralized parties; received data cannot be verifiedFetched when the page opens.

Evidence

StorageBeat

evaluated 2026-10-05

Level 3 of 4Open source; runs no external code without the user's willing, aware consent

StorageBeat, a comparison of decentralised storage services, open source (MIT). It runs no third-party code, which is Level 3. It is not Level 4: when it opens it loads KaTeX's stylesheet from jsDelivr.

Connections
NameLevelNote
KaTeX stylesheet (cdn.jsdelivr.net)Level 1 of 3Relies on centralized parties; received data cannot be verifiedFetched when the page opens.

Evidence

Swapr

evaluated 2026-10-05

Level 2 of 4Supports DDOC

Swapr's exchange app, open source (GPL-3.0); its README names swapr.eth as where releases are published. It is not Level 3: when it opens it loads Fathom's analytics script. It also reads from many endpoints at once: Infura and other RPCs, LI.FI, The Graph, Etherscan, token lists and an unpkg script host.

Connections
NameLevelNote
Fathom analytics (cdn.usefathom.com)Level 1 of 3Relies on centralized parties; received data cannot be verifiedLoaded when the page opens, without asking.
RPC endpoints (Infura, Arbitrum, Gnosis Chain, MEV Blocker)Level 1 of 3Relies on centralized parties; received data cannot be verifiedRead without a light client.
Data services (li.quest, The Graph gateway, api.etherscan.io, token lists)Level 1 of 3Relies on centralized parties; received data cannot be verifiedQuotes, routes and token data, trusted as given.

Evidence

The Lounge

version 4.5.2 · evaluated 2026-10-05

Level 4 of 4Trustless operations (Level 4) and connections (Level 2), except what the user clearly knows is not trustless

A self-hosted IRC client whose server runs inside Orivon on this computer. Its code is open source and it runs only what it ships. Each IRC network is run by its operators, who can read, alter or drop what passes through their servers, and a user joining a network clearly knows that; history and settings stay on this computer, and link previews are off until turned on. That is Level 4 under the exception for evident trust. Not private: each network sees your IP address and what you say.

Operations
NameLevelNote
Send and receive IRC messagesLevel 2 of 5Source code available, and verifiably does what it promisesThe client is open source and does what it promises, but every message passes through servers the network's operators control.
Keep chat history and settingsLevel 4 of 5+ privacyNo centralized or untrusted party can act against the user's interests; privacy: reasonably untrackable and indecipherable without user consentStored only in this app's own files on this computer.
Connections
NameLevelNote
IRC networksLevel 1 of 3Relies on centralized parties; received data cannot be verifiedCentralised servers. TLS protects the link to a server, not the messages from its operators, who also see your IP address.
Link previewsLevel 1 of 3Relies on centralized parties; received data cannot be verifiedWhen turned on, links posted in a channel are fetched from this computer, which tells each linked site your IP address.

Evidence

v1rtl

evaluated 2026-10-05

Level 2 of 4Supports DDOC

v1rtl's blog. It makes no request beyond its own files, but its scripts are a minified build, and the source it links on Radicle could not be fetched from any seed on 2026-10-05, so public source is not established and it stays at Level 2.

Evidence

Velodrome

evaluated 2026-10-05

Level 2 of 4Supports DDOC

Velodrome's trading app on Optimism and other Superchain networks. No public source was found for the frontend (the project publishes contracts, SDKs and docs), so it stays at Level 2. When it opens it reads chain data from Alchemy and dRPC endpoints and contacts WalletConnect's servers.

Connections
NameLevelNote
RPC endpoints (Alchemy, lb.drpc.live)Level 1 of 3Relies on centralized parties; received data cannot be verifiedRead without a light client.
WalletConnect's servers (pulse.walletconnect.org, api.web3modal.org)Level 1 of 3Relies on centralized parties; received data cannot be verifiedContacted when the page opens, before any wallet is connected.

Evidence

Vitalik Buterin's blog

evaluated 2026-10-05

Level 3 of 4Open source; runs no external code without the user's willing, aware consent

Vitalik Buterin's blog. Its source is public (the README dedicates the posts to the public under the WTFPL) and it runs no third-party code, which is Level 3. The home page makes no request of its own. It is not Level 4: some posts load images from other hosts (vitalik.ca, Medium's image server, Imgur, Wikimedia and others) when they are read.

Connections
NameLevelNote
Images in some posts (vitalik.ca, Medium, Imgur, Wikimedia and others)Level 1 of 3Relies on centralized parties; received data cannot be verifiedFetched when a post that uses them is opened.

Evidence

Walletbeat

evaluated 2026-10-05

Level 4 of 4+ privacyTrustless operations (Level 4) and connections (Level 2), except what the user clearly knows is not trustless; privacy: every activity, including connections and operations, is privacy preserving; no connection shows the user to another party, even with consent

Walletbeat, ratings of Ethereum wallets for security and privacy, open source (MIT). Its data ships inside the site: across 80 of its pages it loads only its own files, runs no third-party code and makes no request beyond the site itself.

Operations
NameLevelNote
Browse and compare wallet ratingsLevel 4 of 5+ privacyNo centralized or untrusted party can act against the user's interests; privacy: reasonably untrackable and indecipherable without user consentRuns on this computer; nothing is sent while browsing.

Evidence

Weald Technology

evaluated 2026-10-05

Level 2 of 4Supports DDOC

Weald Technology's site. No public source was found: it is a generated site with a minified script, so it stays at Level 2. When it opens it loads Google Fonts and calls api.vireli.co.

Connections
NameLevelNote
Google Fonts and api.vireli.coLevel 1 of 3Relies on centralized parties; received data cannot be verifiedFetched when the page opens.

WebHash

evaluated 2026-10-05

Level 3 of 4Open source; runs no external code without the user's willing, aware consent

WebHash's website. Its source is public (no licence file) and it runs no third-party code, which is Level 3. It is not Level 4: when it opens it loads Google Fonts and fetches a testimonials widget's settings from Senja.

Connections
NameLevelNote
Google Fonts and wapi.senja.ioLevel 1 of 3Relies on centralized parties; received data cannot be verifiedFetched when the page opens.

Evidence

z0r0z

evaluated 2026-10-05

Level 3 of 4Open source; runs no external code without the user's willing, aware consent

An essay by z0r0z on scaling Ethereum with singleton contracts: one hand-written page served as written, so its source is public, and it runs no script of its own or of others, which is Level 3. It is not Level 4: when it opens it loads images from the ipfs.io gateway and content.wrappr.wtf.

Connections
NameLevelNote
Images (ipfs.io, content.wrappr.wtf)Level 1 of 3Relies on centralized parties; received data cannot be verifiedFetched when the page opens.

Evidence

ZeroLend

evaluated 2026-10-05

Level 2 of 4Supports DDOC

ZeroLend's lending app. The served build matches no public source: the only public frontend is an older, Aave-derived UI, so it stays at Level 2.

Evidence