Know what your
extensions are
really doing

Continuous security analysis across 9 extension marketplaces. Detect malware, secrets, obfuscation, and supply chain risks before they compromise your environment. Use the site, or call the data directly from api.riskyplugins.com through the REST API and hosted MCP endpoint.

9 Marketplaces

Also via OpenVSX

320K+
Extensions Analyzed
9
Marketplaces
2,400+
YARA Rules
24/7
Real-time Monitoring

Security analysis
at every layer

From source code scanning to behavioral analysis, we inspect every dimension of an extension's security posture.

Deep Security Analysis

Multi-engine scanning with YARA malware detection, TruffleHog secret scanning, Horusec SAST, and OSSF Scorecard evaluation. Every extension is dissected layer by layer.

2,400+ YARA malware signatures
Secret & credential detection
Obfuscation & packing analysis

Real-time Monitoring

Continuous scraping and re-analysis catches changes the moment they happen. Track version updates, permission changes, and risk score drift over time.

Continuous marketplace monitoring
Version diff tracking
Historical risk trend analysis

Supply Chain Intelligence

Map dependency trees, identify vulnerable packages, generate SBOMs, and assess developer trust scores. Understand the full supply chain before you install.

Dependency tree mapping
SBOM generation
Developer trust scoring

From install to insight

Three steps to understanding the security posture of any extension in any marketplace.

1

Search or Submit

Search our database of 320,000+ pre-analyzed extensions or submit a new one. Just paste a marketplace URL or extension ID.

2

Deep Analysis

Our multi-engine pipeline scans source code, permissions, network behavior, dependencies, and developer history using 2,400+ security rules.

3

Actionable Scorecard

Get a comprehensive risk scorecard with category breakdowns, specific findings, remediation guidance, and historical risk trends.

Every store,
one platform

Whether your team uses Chrome extensions, VS Code plugins, JetBrains tools, or MCP servers, we have you covered with continuous monitoring across all major extension ecosystems.

Browser Extensions
Chrome Chrome 180K+
Firefox Firefox 35K+
Edge Edge 12K+
IDE Plugins
VS Code VS Code 55K+
JetBrains JetBrains 8K+
Notepad++ Notepad++
OpenVSX OpenVSX 4K+
AI & Automation
MCP Servers MCP Servers 2K+
n8n n8n 1K+

See threats before
they reach you

Our platform surfaces the highest-risk extensions across all marketplaces, giving your security team the intelligence they need to protect your organization.

Explore threat database
Live Threat Feed
Updated 3s ago
DeepSeek to PDF: Export DeepSeek Chats to PDF, Markdown, JSON
CRITICAL 100
webseek
CRITICAL 100
Relaunch
CRITICAL 100
Oorwin AI - Quick Parser
CRITICAL 100
Screenshots for Jira
CRITICAL 100
inTab Pro
CRITICAL 100
Dracula Ebook Online
CRITICAL 100
Subtitles for Youtube
CRITICAL 100
ChatWall - Anonymise & Mask Private Data for AI
CRITICAL 100
Roblox Rewind
CRITICAL 100
Surfchck
CRITICAL 100
橘猫起始页
CRITICAL 100
M1hono Docs Assistant
CRITICAL 100
Cohort
CRITICAL 100
Sidechick
CRITICAL 100
AI Commit Lite
CRITICAL 100
Git Remote Actions
CRITICAL 100
AScript
CRITICAL 100
Lucide Icons
CRITICAL 100
OSS Browser
CRITICAL 100
PlantUML Viewer
CRITICAL 100
pycalc
CRITICAL 100
Another Markdown
CRITICAL 100
PythonScript
CRITICAL 100
office-viewer-pro
CRITICAL 100
as-notes
CRITICAL 100
yarn-spinner
CRITICAL 100
taz-edt-extension
CRITICAL 100
mcp-transport-firewall
CRITICAL 100
docsearch-mcp
CRITICAL 100
@jaewon94/ai-setting
CRITICAL 100
@agentsbazaar/mcp
CRITICAL 100
lucide-angular
CRITICAL 100
lucide-solid
CRITICAL 100
lucide-svelte
CRITICAL 100
@lucide/svelte
CRITICAL 100
Highest risk extensions across all marketplaces View all →

Stop trusting.
Start verifying.

Join security teams who have moved from blind trust to verified security for every extension in their stack.

No credit card required. Free tier includes 100 analyses/month.