OpenVSX Registry Verified

Ruby LSP

036f2a12-40c4-5464-9e05-b82671459271 | v0.10.6
31/ 100
LOW risk
No change since v0.10.4
Analyst verdict
No high-risk signal observed

Based on the RiskyPlugins AI security review of the observed evidence.

Analysis record

Analysed
2 weeks ago
Version
v0.10.6
Artifact
SHA256 EF2…9E8
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

2 detail rows

Publisher Evidence

Low

Shopify

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

55
Noisy-finding weight
x1.00
Publisher domain
No domain
Missing
Store verification signal
Verified publisher
Verified
Extension portfolio
3
Portfolio

12 evidence rows available.

Finding Categories

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality strong.

This extension is a VS Code plugin for connecting with the Ruby LSP, published by Shopify, a well-known and trusted company in the developer tooling space. The extension has 26,553,300 users, indicating widespread adoption and community trust.

Filesystem and Process Access Justification: The two findings in this scan are dependency declarations (DEP-vscode-languageclient-^9.0.1 and DEP-vscode-jsonrpc-^8.2.1 in /extension/package.json). These are the standard libraries required for any VS Code language server extension to communicate with the Language Server Protocol. Language servers legitimately need to read source code files to provide intellisense, code completion, diagnostics, and navigation features. This is the core purpose of the extension as stated in its description. No findings indicate unauthorized file access beyond what a language server requires.

Credential Access: The scan shows zero secret findings and zero credential-access findings. There is no evidence of attempts to read .env files, .git/config, SSH keys, cloud credentials, or VS Code secret storage. The threat_indicators field shows "secret":"0", confirming no credential theft patterns were detected.

Strongest Counterargument: A skeptic might argue that any extension with workspace access could potentially exfiltrate code. However, this extension has zero malware signatures ("malware-signature":"0"), zero IoC hits ("ioc":"0"), zero obfuscation findings ("obfuscation":"0"), and zero network activity flags ("network":"0"). The absence of these indicators, combined with Shopify's reputation and 26+ million users, makes malicious intent implausible. The only findings are legitimate dependency declarations that any VS Code extension requires.

This is a clean scan of a legitimate development tool. The automated scanner flagged normal package.json dependencies as findings, but these represent expected behavior for a language server extension, not security concerns.

Key Reasons

  • Zero malware signatures, IoC hits, or obfuscation findings detected
  • Only findings are standard VS Code language server dependencies in package.json
  • Published by Shopify, a well-known legitimate company
  • 26+ million users indicates widespread trust and adoption
  • No credential access or suspicious network activity detected

False Positive Considerations

  • Dependency findings flagged as security issues when they are normal package.json declarations
  • No actual malicious patterns detected in code or network activity
  • Standard VS Code language server libraries misidentified as security findings

Reviewed 2026-05-23; recommended action: no action; model confidence 95%.

Open VSX version history

Risk trend by version

5 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
31
Change since first
No change
Change from previous
No change
Versions:
First analyzed version
0.10.1
Mar 22, 2026
Risk range
31 to 31
Across analyzed versions
Latest analyzed version
0.10.6
Aug 1, 2026
Selected version
low
Version
v0.10.6
2 months ago
Risk score
31
Findings
2
Change vs previous
No change

Pick any point on the chart to explore that version's code below.

About This Extension

VS Code plugin for connecting with the Ruby LSP

Frequently Asked Questions