Skip to content
Back to skills

2591 Incorrect Constructor 63cf3819

ASecurity

- Solidity version <0.4.22 where constructors are named functions matching the contract name - The function name does not exactly match the contract name (typo, case mismatch, or contract renamed without updating the constructor)

  • 9 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added October 11, 2026
blockchaingit

Security analysis

A100/100

Scanned October 11, 2026

npx -y skills add tools-only/X-Skills --skill 2591-incorrect-constructor_63cf3819 --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of 2591 Incorrect Constructor 63cf3819?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for 2591 Incorrect Constructor 63cf3819
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/tools-only-2591-incorrect-constructor-63cf3819/badge)](https://www.skillsdirectory.com/skills/tools-only-2591-incorrect-constructor-63cf3819)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

SKILL.md
# Incorrect Constructor Name

## Preconditions
- Solidity version <0.4.22 where constructors are named functions matching the contract name
- The function name does not exactly match the contract name (typo, case mismatch, or contract renamed without updating the constructor)

## Vulnerable Pattern
```solidity
// Solidity <0.4.22: constructor is a named function
contract Owned {
    address public owner;

    // Typo: "owned" != "Owned" (case mismatch)
    // This becomes a regular public function anyone can call
    function owned() public {
        owner = msg.sender;
    }
}

// Contract renamed but constructor not updated
contract Treasury {
    address public owner;

    // Was "Wallet" before rename — now a regular public function
    function Wallet() public {
        owner = msg.sender;
    }
}
```

## Detection Heuristics
1. Check the Solidity version: if >=0.4.22 and the `constructor` keyword is used, this vulnerability does not apply
2. For <0.4.22 contracts: find the function that sets initial state (owner, parameters) and verify its name exactly matches the contract name (case-sensitive)
3. Search for public/external functions that set `owner` or perform one-time initialization — these may be misnamed constructors
4. Check if the contract was renamed at any point (git history, comments) but the constructor function was not updated
5. Flag any named function that appears to perform initialization logic (sets owner, initializes critical state) but doesn't match the contract name

## False Positives
- Solidity >=0.4.22 using the `constructor` keyword (enforced by compiler)
- The function is intentionally a public initializer (e.g., in proxy patterns) with proper access control

## Remediation
- Upgrade to Solidity >=0.4.22 and use the `constructor` keyword
- For legacy contracts, verify the constructor function name exactly matches the contract name
```solidity
// Modern Solidity: compiler-enforced constructor
contract Owned {
    address public owner;

    constructor() {
        owner = msg.sender;
    }
}
```

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…