Is the source published and does it match?
A verified contract on the explorer means the published source compiles to the deployed bytecode. Unverified means you are trusting bytecode nobody has shown you, which for anything holding value is reason enough to stop.
Verified is a floor, not a conclusion. It tells you what the code is; it does not tell you the code is benign.
Who can change what?
Scan the function list for owner-restricted entries: mint, pause, setFee, blacklist, setRouter, upgradeTo. Each one is a power someone holds right now. Check who the owner is — an individual key, a multisig, a timelock, or nothing.
If the contract is behind a proxy, the implementation can be swapped. Find out who can perform that swap and whether a delay applies.
What does the on-chain history say?
Deployment age, number of holders, transaction count and whether activity looks organic. A contract deployed yesterday with concentrated holdings and heavy promotion is a specific pattern, not a coincidence.
For a token, look at the liquidity pool: size, lock status and whether the deployer still holds the LP tokens.
Age is weak evidence on its own and it is cheap to check. A contract that has held significant value for a year without incident has survived scrutiny a contract deployed this morning has not. That is not a guarantee of anything; it is a different starting assumption.
Simulate before committing
Many wallets preview the balance changes a transaction will produce. Read that preview — it converts an opaque call into "you will lose X and gain Y", which is the only summary that matters.
For a token you intend to hold, buy a trivial amount and test a sale first. Two gas fees is cheap insurance against a one-way contract.