Snapline — Code Screenshots
The AI review rates the findings as likely false positive, but the risk score (46/100) still counts them.
Analysis record
- Analysed
- 2 days ago
- Version
- v0.1.1
- Artifact
- SHA256 2C5…BF7
- Source
- Findings (non-IoC)
Is Snapline — Code Screenshots safe?
The snapline-code-screenshots extension turns your active code into shareable images. It operates entirely within the editor interface and declares no special host permissions. To support its freemium model, it connects to api.gumroad.com to verify license keys and includes links to a Gumroad storefront for premium upgrades.
Security scanners flagged a credential environment file match inside the bundled webview and extension scripts. If this were a real threat, it would mean the extension was secretly reading your private environment variables and sending them to an external server. The scanner also flagged several web addresses, including property chains like dataset.bg that it mistook for actual domains.
These alerts are scanner noise. The credential match is a generic pattern triggered by standard JavaScript bundled in the distribution files, not an actual attempt to read your private configuration. The web addresses are either legitimate Gumroad links for license verification or standard XML schema URLs pulled in by a background library. The extension simply reads your active editor text to render an image and checks your license status, which is exactly what it is supposed to do.
No Findings
All security checks passed
Publisher Evidence
Limited evidencebranchline
Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
12 evidence rows available.
No Threats Detected
This extension passed all security checks
AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality strong.
The snapline-code-screenshots extension provides a straightforward utility for developers: rendering the active editor text into a shareable image. To accomplish this, it reads the contents of the current file in the editor. This filesystem access is entirely justified by the tool's stated purpose. The extension declares no special host permissions or broad workspace access in its manifest, relying instead on the standard Visual Studio Code API to access the active document. It does not spawn external processes or execute shell commands.
When examining the credential-access findings, the scanner flagged YARA--credential_env_files matches inside dist/extension.js and dist/webview.js. These are classic code-smell false positives. The YARA rule triggers on basic JavaScript patterns that reference environment variables or DOM properties within bundled, minified distribution files. The extension does not read .env files, SSH keys, or cloud credentials from the user's workspace. There are zero secret-exfiltration findings in the bundle.
The network endpoints identified in the analysis point to a legitimate freemium business model rather than malicious data collection. The extension communicates with api.gumroad.com/v2/licenses/verify to check license keys, and includes links to dealership6.gumroad.com for support and pro version upgrades. Gumroad is a standard digital distribution platform. The other flagged domains, such as r.dataset.bg, e.target.dataset.bg, and month.abb, are not real network destinations. They are JavaScript property access chains and date-formatting variables that the XIOC extractor misinterpreted as domains. Additionally, the scanner flagged http://schemas.openxmlformats.org/package/2006/content-types. This is a standard XML namespace URL used by document generation libraries, likely included as a transitive dependency for exporting screenshots to various formats. It does not indicate unauthorized data transmission.
The strongest counterargument to a clean bill of health is the combination of a very low user count on OpenVSX and the presence of postinstall YARA matches. A skeptical reviewer might worry about a new extension with postinstall hooks. However, the YARA--postinstall_file_manipulation match occurs in package.json, and the YARA--postinstall_registry_modification match occurs in LICENSE.txt. These are just standard text files triggering overly broad pattern-matching rules. There is no actual postinstall script executing arbitrary payloads. The extension is a clean, functional tool with a standard monetization layer, and the scanner noise is entirely attributable to bundled JavaScript and generic YARA rules.
Key Reasons
- All IoC domains are JavaScript property access chains misinterpreted as network endpoints
- Network calls are limited to legitimate Gumroad license verification and support URLs
- Credential YARA matches in dist files are standard code-smell false positives on bundled JavaScript
- Postinstall YARA matches trigger on standard package.json and LICENSE.txt text files
- Extension declares no special permissions and relies on standard editor APIs to read active text
False Positive Considerations
- XIOC extractor misinterpreting JavaScript property access chains as domains
- YARA code-smell rules triggering on bundled minified JavaScript
- Overly broad YARA postinstall rules matching standard package.json and LICENSE.txt files
Reviewed 2026-10-01; recommended action: suppress false positive; model confidence 95%.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace