Islamic Finance Principles Assessment
Riba — Does GoPlus Security involve interest?
GoPlus's core business — fee-for-service security data and detection — generates revenue through App transaction fees, SafeToken B2B services, and SaaS subscriptions, none of which are interest-based. However, its staking product explicitly promises a "base APY" alongside variable dividends and buybacks, introducing a fixed-return element that resembles riba. Muslim investors should treat the base protocol's fee model as acceptable but approach the staking product with caution.
Assessment: Moderate Riba
Score: 56.6/100
Our methodology examines 10 criteria to evaluate how well GoPlus Security avoids interest-based mechanisms.
GoPlus generates roughly $4.27M-$4.7M in cumulative revenue (as of October 2025) through the GoPlus App, SafeToken B2B token-management services, and SaaS subscriptions — a fee-for-service model consistent with permissible trade income, not lending or interest. No lending/borrowing function exists within the base protocol. However, treasury composition is not disclosed in available sources, so it cannot be confirmed whether idle reserves are held in interest-bearing instruments, leaving some residual uncertainty around treasury management practices.
The 500M-GPS Security Fund staking program advertises "triple returns": a fixed base APY, ecosystem safety dividends (funded by partner airdrops), and deflation-driven buybacks tied to protocol activity. The dividend and buyback components are variable and performance-linked, which fits a profit-sharing structure more comfortably. The fixed base APY, however, functions like a guaranteed interest payment regardless of underlying protocol performance, which is the more concerning element from a riba perspective and warrants avoidance by cautious investors.
Gharar — How much uncertainty does GoPlus Security involve?
GoPlus carries moderate uncertainty: a named, verifiable team and real product usage reduce ambiguity, while the absence of a dated formal audit and undisclosed treasury details increase it. On balance, the uncertainty here is more about disclosure gaps than an inherently deceptive design.
Assessment: Moderate Gharar (Material Uncertainty)
Score: 55.5/100
Our methodology examines 15 criteria including team transparency, audit quality, and governance.
The founding team — Mike (Yufeng Xu), Eskil Xu, and CTO Allen Zhang — is named and traceable, with documented prior roles at Qihoo 360, Ant Group, and blockchain ventures Delphy and Yixuan Tech. The project raised $10M from OKX Ventures, HashKey Capital, and Animoca Brands, and integrates with CoinMarketCap, CoinGecko, DEXTools, and MetaMask. This transparency meaningfully reduces gharar. However, full open-source status of core contracts is only weakly evidenced through a single CertiK flag, leaving code-level transparency somewhat unresolved.
No named, dated formal audit of GoPlus Security's own smart contracts was located in available sources; Halborn audit reports found concern unrelated protocols, and CertiK Skynet only provides an automated score (code security 80, governance 70.5) rather than a comprehensive audit. This absence of a genuine third-party audit is a real gharar concern and should be named plainly rather than minimized. Additionally, staking's custody model, lock-up duration, and slashing conditions are not detailed, further limiting risk disclosure for participants.
Maysir — Does GoPlus Security involve gambling or speculation?
Although GPS is categorized in the meme-coin bracket, its actual design — a security-data utility token with staking, governance, and real fee revenue — does not resemble a purely speculative instrument. Some secondary-market speculation is inevitable for any listed token, but this is not unique to GPS's design. The base protocol itself is oriented toward productive function rather than gambling-like speculation.
Assessment: Moderate Maysir (High Risk)
Score: 66.4/100
Our methodology examines 11 criteria to determine whether GoPlus Security is a gambling instrument or a genuine economic tool.
Unlike typical meme coins built solely on hype and social momentum, GPS's evidence base shows a functioning security-data service with 125K+ daily users and 21M+ transactions protected, revenue-generating B2B and SaaS lines, and staking tied to compute/data-provider roles. This genuine operational layer weakens any resemblance to maysir, since the token's value proposition is anchored in fee-generating utility rather than pure price speculation. The meme-coin classification appears to reflect market listing conventions rather than the project's actual design or intended function.
Weighing the evidence, GoPlus shows real utility — integrations across major wallets and data platforms, node-operator staking, and disclosed revenue streams — that meaningfully offsets speculative concerns. That said, GPS still trades on open exchanges including Binance, where price action can be driven by sentiment and volatility independent of underlying usage, as with most liquid tokens. This secondary-market speculation is a general market feature rather than a maysir-designed characteristic of GPS itself, and should not be conflated with the protocol's own purpose.
The Full 27-Point Screening
1. Legitimacy (4 criteria)
| Criterion | Score | Analysis |
|---|
| Team Transparency | 85/100 | Named team members with verifiable, traceable professional histories are documented across multiple sources. |
| Fraud & Scam Risk | 80/100 | No fraud, hack or rug-pull indicators found for GoPlus itself; it operates as a recognized anti-scam service with reputable VC backing. |
| Use Case Legitimacy | 88/100 | Clear, widely-adopted real-world utility as Web3 security infrastructure across major platforms and wallets. |
| Ethical Practices | 88/100 | The protocol's own design is a fraud/scam-detection and protection service; any misuse of its detection data by unrelated third parties does not change the coin's own legitimate purpose. |
Summary: GoPlus Security has a publicly named, credentialed founding team and an established, reputable track record as a Web3 anti-scam detection firm with no fraud or hack indicators found.
2. Project Operations (9 criteria)
| Criterion | Score | Analysis |
|---|
| Core Protocol Business | 88/100 | Core business is security/data infrastructure, not a prohibited sector. |
| Transaction Fees | 65/100 | Fees are paid in GPS for services with portions used for rewards and buyback/deflation, but the complete fee-flow mechanics are only partially disclosed. |
| Treasury Assets | 45/100 (low evidence) | The sources provide no information on treasury asset composition or whether reserves involve interest-bearing instruments. |
| Revenue Model | 78/100 | Revenue is generated from service and subscription fees, not from interest-based lending activity. |
| Transparency | 60/100 | Extensive documentation exists and a third-party scan flags "open source" contracts, but full core-protocol code transparency is not confirmed. |
| Governance | 55/100 | Governance utility exists via staking/voting and a third-party rating calls governance "relatively good," but centralization details are unclear. |
| Launch Fairness | 40/100 | Tokens were distributed to private SAFT investors and the team ahead of public trading, indicating insider pre-access rather than a fully fair launch. |
| Token Distribution | 55/100 | A majority (60.67%) is allocated to community/ecosystem with the remainder to team/investors under multi-year vesting — moderately broad but insider-weighted. |
| Speculation/Utility Ratio | 65/100 | The token has defined utility roles (fees, staking, governance), though the degree of speculative trading versus utility use is not detailed. |
Summary: The base protocol is a genuine security/data infrastructure layer with fee-based utility, though token launch involved a private investor round and team allocation ahead of the public airdrop.
3. Financial Health (4 criteria)
| Criterion | Score | Analysis |
|---|
| Protocol Revenue | 78/100 | Revenue streams are service-fee based rather than interest-derived. |
| Financial Status | 68/100 | Disclosed, growing revenue and credible funding history indicate reasonable financial transparency, though profitability and runway are not detailed. |
| Interest Assessment | 50/100 | The base protocol lacks a lending/borrowing market, but its staking product explicitly advertises a fixed "base APY," which carries interest-like characteristics. |
| Audit Quality | 20/100 (low evidence) | No named, dated audit report specific to GoPlus Security's own smart contracts was found; located Halborn reports concern unrelated projects and CertiK Skynet is an automated scan, not a full audit. |
Summary: The protocol generates real, disclosed service-fee revenue rather than interest income, but no named formal audit of its own smart contracts could be found in the sources.
4. Token Economics (5 criteria)
| Criterion | Score | Analysis |
|---|
| Token Purpose | 78/100 | GPS functions as a utility token for fee payment, staking, and governance rather than a purely speculative meme token. |
| Governance Rights | 55/100 | Staking is stated to grant governance rights over bounty submissions, but the scope of voting mechanics is not fully detailed. |
| Rewards Distribution | 42/100 | Staking rewards combine a fixed base APY with variable dividends and deflation-driven buybacks, blending interest-like fixed elements with performance-based ones. |
| Speculation Controls | 35/100 | Aside from standard team/investor vesting schedules, no dedicated anti-speculation mechanisms are described. |
| Asset Backing | 55/100 | Token value is tied to protocol utility and fee generation rather than hard-asset backing, but this is not deeply documented. |
Summary: GPS is a functional utility token for fees, staking, and governance, though its staking rewards mix fixed APY-style payouts with variable elements.
5. Staking Mechanism (5 criteria)
| Criterion | Score | Analysis |
|---|
| Mechanism Type | 55/100 | Staking can be direct or delegated to compute/data-provider roles, but custody model, lock-up and withdrawal terms are not clearly specified. |
| Islamic Contract Classification | 30/100 | The advertised fixed "base APY" component resembles a guaranteed increment rather than a clean Mudarabah/Wakalah profit-sharing structure, leaving the contract classification unresolved. |
| Rewards Structure | 35/100 | Rewards are explicitly a mix of fixed APY, dividends, and deflation boosts rather than being purely variable and tied to genuine underlying activity. |
| Documentation | 55/100 | Whitepaper covers staking and governance roles at a high level, but detailed risk disclosures, lock-up terms, and slashing conditions are absent from these sources. |
| Shariah Alignment | 35/100 | The fixed-APY element within the staking reward structure represents an unresolved core Shariah question around guaranteed return that weighs against a clean alignment finding. |
Summary: A native staking mechanism exists, allowing users to stake or delegate GPS for network security roles and rewards, but the fixed-APY component raises an unresolved Shariah classification question and documentation on custody/lock-up terms is incomplete.
Overall Assessment: GoPlus Security appears to be a legitimate, utility-driven security infrastructure project with a credible team and real revenue, but its staking reward design and lack of a verifiable third-party audit are the main areas of unresolved Shariah concern.
Scoring note: Meme coin: maysir-capped (C13=65); score already below the cap.