Skip to content
CAI
Software that uses CAICheck a score

mortdeus/solana-copy-sniper-mev-trading-bot

33.1

Weak · 30 September 2026

6.9k

lines of production code

Rust

with JavaScript

2

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a Solana trading bot infrastructure that evolved from a legacy C compiler component into a modern blockchain application. It currently provides core trading capabilities and integrates with the Jito Block Engine via a JSON-RPC client. Recent activity indicates a strong focus on maintaining security posture through dependency and configuration updates rather than feature development.

How it got here

2013 — Add support for struct types and structure member access

1 change.

The C compiler in the prestruct directory now supports the struct keyword and structure member access using the dot (.) and arrow (-\>) operators. This change introduces a new 'struct' type (token 4) in the symbol table, adds parsing logic in the expression builder to handle structure references, and implements code generation for structure field offsets and indirection. The symbol table lookup is also updated to mark structure symbols as non-deletable.

September 2025 — Initial infrastructure setup

2 changes.

This period focused on establishing the foundational components for Solana trading bots. The work involved creating the initial dependency manifests and releasing the first version of the Jito Block Engine JSON-RPC client alongside the core trading infrastructure.

Week 39 of 2026 (21 Sep – 27 Sep) — Security remediation

2 changes.

The period focused on addressing security vulnerabilities, with 366 findings resolved and 19 regressions identified. The work was conducted without code commits, suggesting the changes were likely managed through configuration updates, dependency patches, or automated tooling rather than manual code modifications.

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 32 → 33 (+0.8)
  • Rubric changed (rubric-2026.09.11 → rubric-2026.09.18) — scores are not directly comparable.

Lenses

  • Code Health 58 → 58 (-0.1)
  • Architecture 60 → 66 (+5.4)
  • Maturity 72 → 72 (+0.0)
  • Readiness 8 → 10 (+1.9)
  • Security 73 → 67 (-6.5)
  • Accessibility 40 → 40 (-0.8)
  • Performance 100 (new)

Resolved (367)

  • Critical CVE: [CVE redacted] (1_solana sniper bot(node) using gRPC/package-lock.json)
  • Critical CVE: [CVE redacted] (1_solana sniper bot(node) using gRPC/package-lock.json)
  • Critical CVE: [CVE redacted] (2_copy trading bot(node) using gRPC/package-lock.json)
  • Critical CVE: [CVE redacted] (2_copy trading bot(node) using gRPC/package-lock.json)
  • Critical CVE: [CVE redacted] (3_sniper bot(node) using using Helius websocket/package-lock.json)
  • Critical CVE: [CVE redacted] (3_sniper bot(node) using using Helius websocket/package-lock.json)
  • Critical CVE: [CVE redacted] (1_solana sniper bot(node) using gRPC/package-lock.json)
  • Critical CVE: [CVE redacted] (2_copy trading bot(node) using gRPC/package-lock.json)
  • Critical CVE: [CVE redacted] (3_sniper bot(node) using using Helius websocket/package-lock.json)
  • Critical CVE: [GHSA redacted] (1_solana sniper bot(node) using gRPC/package-lock.json)
  • Critical CVE: [GHSA redacted] (1_solana sniper bot(node) using gRPC/package-lock.json)
  • Dependency hygiene PARTLY measured — npm pinning read, dependency currency not (no pnpm-resolved versions to grade)
  • High CVE: [CVE redacted] (1_solana sniper bot(node) using gRPC/package-lock.json)
  • High CVE: [CVE redacted] (2_copy trading bot(node) using gRPC/package-lock.json)
  • High CVE: [CVE redacted] (3_sniper bot(node) using using Helius websocket/package-lock.json)
  • High CVE: [CVE redacted] (1_solana sniper bot(node) using gRPC/package-lock.json)
  • High CVE: [CVE redacted] (2_copy trading bot(node) using gRPC/package-lock.json)
  • High CVE: [CVE redacted] (3_sniper bot(node) using using Helius websocket/package-lock.json)
  • High CVE: [CVE redacted] (1_solana sniper bot(node) using gRPC/package-lock.json)
  • High CVE: [CVE redacted] (2_copy trading bot(node) using gRPC/package-lock.json)
  • …and 347 more

New (28)

  • Banned license: @raydium-io/raydium-sdk
  • Critical CVE: [GHSA redacted] (1_solana sniper bot(node) using gRPC/package-lock.json)
  • Critical CVE: [GHSA redacted] (1_solana sniper bot(node) using gRPC/package-lock.json)
  • Dependency hygiene PARTLY measured — Cargo dependencies read, no committed lock to grade for currency
  • Duplicate RPC client instances. Both AppState and Pump structs maintain two separate fields for RPC clients: one blocking (rpc_client) and one non-blocking (rpc_nonblocking_client). This duplicates state management and initialization logic across multiple structs.
  • High CVE: [GHSA redacted] (1_solana sniper bot(node) using gRPC/package-lock.json)
  • High CVE: [GHSA redacted] (1_solana sniper bot(node) using gRPC/package-lock.json)
  • High CVE: [GHSA redacted] (1_solana sniper bot(node) using gRPC/package-lock.json)
  • High CVE: [GHSA redacted] (1_solana sniper bot(node) using gRPC/package-lock.json)
  • High CVE: [GHSA redacted] (1_solana sniper bot(node) using gRPC/package-lock.json)
  • High CVE: [GHSA redacted] (1_solana sniper bot(node) using gRPC/package-lock.json)
  • High CVE: [GHSA redacted] (1_solana sniper bot(node) using gRPC/package-lock.json)
  • High CVE: [GHSA redacted] (1_solana sniper bot(node) using gRPC/package-lock.json)
  • Identical types defined in multiple service modules. BundleStatus is defined identically in jito and zeroslot services.
  • Identical types defined in multiple service modules. TipAccountResult is defined identically in jito, nextblock, and zeroslot services, violating DRY principles and creating maintenance overhead.
  • Malicious package: MAL-2025-21003 (1_solana sniper bot(node) using gRPC/package-lock.json)
  • Massive redundancy in instruction generation methods. For every action (initialize, set_params, create, buy, sell, withdraw), there are 6 distinct methods differing only by whether they take a program_id, keys vs accounts, or require signing seeds. This creates a 6x explosion of API surface for identical logical operations.
  • Medium CVE: [GHSA redacted] (1_solana sniper bot(node) using gRPC/package-lock.json)
  • Medium CVE: [GHSA redacted] (1_solana sniper bot(node) using gRPC/package-lock.json)
  • Medium CVE: [GHSA redacted] (1_solana sniper bot(node) using gRPC/package-lock.json)
  • …and 8 more

Changes since last survey

  • 1 commits — 1 feature/other, 0 fixes

By area

  • (root) — 1 commit

Notable commits

  • change: Update README.md

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

mortdeus/solana-copy-sniper-mev-trading-bot was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 30 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 5d92c31aa494e8e8b8004674267a9dd542fae5df — the exact code this score is about.
  • Scored under rubric-2026.09.18 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-cb25ca4feafa.