VS Code Marketplace

Better PL/SQL

by Danil Reznichenko · 637 users · 5.0 rating
0000bee7-8c5d-55b5-a531-d05887d7b845 | v2.0.1
38/ 100
LOW risk
Risk verdict
No high-risk signal observed

Score-based assessment (low risk, 38/100). No analyst review available.

Analysis record

Analysed
8 months ago
Version
v2.0.1
Artifact
SHA256 957…7A8
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

10 detail rows

YARA Rule Matches

6 rules
SeverityRuleHitsFilesMetadata
HIGHpostinstall network communication

Network communication detected

2
LICENSE.txtsyntaxes/plsql.tmLanguage
Risky Plugins Authors FP 30%
HIGHpostinstall file manipulation

File system manipulation detected

3
snippets/plsql.snippets.jsonsyntaxes/plsql.configuration.jsonsyntaxes/plsql.tmLanguage
Risky Plugins Authors FP 20%
HIGHpostinstall system command

System command execution detected

1
syntaxes/plsql.tmLanguage
Risky Plugins Authors FP 10%
HIGHpostinstall crypto operations

Cryptographic operations detected

1
syntaxes/plsql.tmLanguage
Risky Plugins Authors FP 30%
HIGHpostinstall file download

File download activity detected

2
syntaxes/plsql.tmLanguageCHANGELOG
Risky Plugins Authors FP 30%
HIGHpostinstall obfuscation

Code obfuscation techniques detected

1
syntaxes/plsql.tmLanguage
Risky Plugins Authors FP 20%

Network Indicators

Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.

30 total
...

Network indicators are queued for lazy loading

Scroll this section into view to load the detailed rows.

Publisher Evidence

Limited evidence

Danil Reznichenko

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

34
Noisy-finding weight
x1.00
Publisher domain
No domain
Missing
Store verification signal
Not exposed
Not exposed
Extension portfolio
2
Portfolio

13 evidence rows available.

Finding Categories

10
Malware Signatures
30
IoC Indicators

YARA Rules Matched

6 rules(10 hits)
postinstall network communication postinstall file manipulation postinstall system command postinstall crypto operations postinstall file download postinstall obfuscation

Security Analysis Summary

Security Analysis Overview

Better PL/SQL is a Visual Studio Code Marketplace extension published by Danil Reznichenko. Version 2.0.1 has been analyzed by the Risky Plugins security platform, receiving a risk score of 38.08/100 (LOW risk) based on 40 security findings.

Risk Assessment

This extension presents low security risk. Some minor findings were detected, but nothing that would prevent typical usage. Reviewing the detailed findings below is recommended before use in sensitive environments.

Findings Breakdown

  • High: 10 finding(s)
  • Medium: 30 finding(s)

What Was Analyzed

The security assessment covers multiple analysis categories:

  • Malware Detection: YARA rule matching against 2,400+ malware signatures
  • Secret Detection: Scanning for exposed API keys, tokens, and credentials
  • Static Analysis: Code-level security analysis for common vulnerability patterns
  • Network Analysis: Detection of suspicious network communications and endpoints
  • Obfuscation Detection: Identification of code obfuscation techniques

Developer Information

Better PL/SQL is published by Danil Reznichenko on the Visual Studio Code Marketplace marketplace. The extension has approximately 637 users.

Recommendation

Exercise caution with this extension. Review the detailed findings and ensure the requested permissions align with the extension's stated functionality before installation.

About This Extension

Syntax highlighting and snippets for Oracle PL/SQL in VS Code, Cursor, and other VS Code-compatible editors

Frequently Asked Questions