The AI review rates the findings as likely false positive, but the risk score (44/100) still counts them.
Analysis record
- Analysed
- 5 days ago
- Version
- v3.11.10
- Artifact
- SHA256 CB5…277
- Source
- Findings (non-IoC)
Is Shopify Liquid safe?
Theme Check is Shopify's official linter for Shopify themes. It runs inside your editor, reads the Liquid and JSON files in your theme folder, flags errors and bad practices, and can auto-fix them when you accept the fix. This extension declares no special permissions, so the scan judged it purely on what its bundled code contains.
The scan returned 32 network-related findings, all of them pattern matches inside Shopify's own minified build files, for example NET-SOCKET_IO-extension/dist/browser/extension.js-36782 and NET-FETCH-extension/dist/node/server.js-50440. If one of these were real, it would mean the extension opens network connections from code it ships, which in a bad extension could be used to send your code or credentials off your machine. The catch is that the scanner attached no web address to any of these calls, and the same scan found no suspicious web addresses, no malware signatures, and no secret or credential material anywhere in the extension.
That is why these findings don't add up to a problem. The scanner tripped on fetch, XMLHttpRequest and Socket.IO plumbing inside build output at paths like extension/dist/browser/server.js, the same JavaScript calls nearly every bundled extension contains, and it found nothing that reads .env files, SSH keys or cloud credentials, and no server for anything to connect to. The findings describe a linter talking to your editor and to Shopify, with the scanner counting standard network calls in minified code.
No Findings
All security checks passed
Publisher Evidence
LowShopify
Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
12 evidence rows available.
No Threats Detected
This extension passed all security checks
AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality moderate.
What this extension does
teme-check-vscode (v3.11.10) is Shopify's Theme Check, the standard linter for Shopify Liquid themes, listed with 113,777 installs. It ships a language server in two builds: extension/dist/node/server.js for desktop use and extension/dist/browser/server.js for the browser editor, plus companion bundles at extension/dist/browser/extension.js and extension/dist/node/extension.js. A language server reads the theme files in your workspace, runs lint rules over them, and sends diagnostics back to the editor. That job needs filesystem access, a running server process, and network plumbing to move messages between the server, the editor, and Shopify's services.
What the scanner flagged
Every finding in this scan is a medium-severity network pattern match: NET-FETCH-extension/dist/browser/server.js-7289, NET-XMLHTTPREQUEST-extension/dist/browser/extension.js-7575, NET-SOCKET_IO-extension/dist/browser/extension.js-36782, and the rest spread across extension/dist/node/server.js, extension/dist/node/extension.js, and extension/dist/browser/server.js. These titles record that the scanner saw fetch, XMLHttpRequest, and Socket.IO usage inside minified build output. Nearly every bundled JavaScript extension contains those APIs; detecting them tells you the code makes network calls, and nothing more. The scan attached no web address to any of these calls, so there is no destination behind any of the 32 findings.
Credentials and secrets
The scan produced no secret findings, no credential-access findings, and no tool-poisoning findings. Nothing in extension/dist/node/server.js or any other flagged file reads .env files, SSH keys, or cloud credentials. Theme Check reads .liquid files and theme JSON config because a linter must read the code it lints, and it writes fixes back to those same files when you accept an autocorrect. That is ordinary linter behavior confined to the theme directory.
The strongest counterargument
The Socket.IO match at extension/dist/browser/extension.js-36782 deserves the hardest look. A persistent socket channel inside a browser bundle would, in a malicious extension, work well as a live command path to an attacker's server. Two facts defuse it. The scan found no endpoint associated with that call, so there is no address to be worried about, and Socket.IO routinely enters bundles as a transitive dependency of a packaged library rather than as code the extension authors wrote. A skeptic could also ask whether this OpenVSX listing is a re-upload rather than Shopify's own. The listing names Shopify as the developer and holds a six-figure install base (113,777), consistent with the official Theme Check distribution rather than a counterfeit.
Nothing in this scan shows behavior beyond linting Shopify themes. The flagged files are build output, the flagged calls have no destinations, and the categories that carry real signal (indicators of compromise, malware signatures, secrets, obfuscation) all came back empty.
Key Reasons
- All 32 findings are generic network API pattern matches (NET-FETCH, NET-XMLHTTPREQUEST, NET-SOCKET_IO) inside minified dist/ build output
- Zero IoC, malware-signature, obfuscation, secret, and tool-poisoning findings
- Official Shopify extension (113,777 installs on OpenVSX) whose stated purpose, linting Shopify Liquid themes via a language server, explains the bundled server and network plumbing
- No credential-access findings: nothing targets .env files, SSH keys, or cloud credentials
- No network endpoints were extracted from the flagged calls, so none of the findings has a suspicious destination
False Positive Considerations
- Network API pattern matching (fetch, XMLHttpRequest, Socket.IO) against minified dist/ bundles
- Bundled language server code (extension/dist/node/server.js, extension/dist/browser/server.js) generating repeated medium-severity network hits
- Pattern-only findings with no extracted endpoints or corroborating IoC, malware, secret, or obfuscation evidence
Reviewed 2026-09-26; recommended action: suppress false positive; model confidence 90%.
Open VSX version history
Risk trend by version
2 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace