Please note the rating has been upgraded to 4 as shown in the reply below.
Security Rating Level: 5
Evaluation Date: Mar 31st, 2021
1. History & Team (Weight 20%; Score 80)
1.1 Project age (8%; 100)
Launched on mainnet from 2018 July, alive for 33 months.
1.2 Past exploits (8%; 50)
Was Attacked 1 time in 2020 Nov (~$90mil liquidation)
1.3 Team anonymity (2%; 100)
Team are public
1.4 Team experience in programming (2%; 100)
CTO and founder, Geoffrey Hayes, experience of programming started from 2008
2. Exposure (Weight 25%; Score 89.5)
2.1 Historical TVL (17.5%; 100)
Average market share in the past 4Q: 12.0%, 11.3%, 12.8%, 13.2%
Data collected from Compound | Stats, Charts and Guide | DeFi Pulse
2.2 Industry segment (5%; 85)
Compound is a lending protocol (no flashloan allowed)
2.3 Infrastructure (2.5%; 25)
Use Coinbase pro to feed price (single centralized oracle), plus sanity check using Uniswap price data (price monitor exists)
3. Audit (Weight 35%; Score 100)
Audit report available on: Compound | Docs - Security
3.1 Transparency and scope (14%; 100)
Full scope audit done, and report is public
3.2 Audit firm trust score (10.5%; 100)
Audited by Trail of bits and OpenZeppelin, Tier 1 audit firm
3.3 Audit findings (10.5%; 80)
No critical issues found in audit
3.4 Other credits (up to additive 5.25%; 10)
Core smart contracts audited by multiple firms, Formal verification done
4. Code quality (Weight 15%; Score 95)
Repository on github: GitHub - compound-finance/compound-protocol: The Compound On-Chain Protocol
4.1 Documentation
Excellent documentation.
4.2 Test
Comprehensive test done, with code coverage 44%
5. Developer community (Weight 5%; Score 90)
5.1 Bug bounty program (3.5%; 90)
Exists. Reward up to $150,000
5.2 Issues raised on Github (1.5%; 90)
11 issues raised on github repository. Score = 90.
The N-SCOSS for Compound is 92.125, level 5