VS Code Marketplace Verified

Jupyter Notebook Renderers

by Microsoft · 88.4M users · 2.9 rating
08fc0d4e-4782-59de-adb8-46d4e6f26e75 | v1.3.2025062701
0/ 100
MINIMAL risk
Analyst verdict
Benign but powerful

From the RiskyPlugins AI security review of the observed evidence.

No individual score drivers were recorded for this analysis.

Analysis record

Analysed
10 months ago
Version
v1.3.2025062701
Artifact
SHA256 CFA…E0C
Source
Findings (non-IoC)

No Findings

All security checks passed

Publisher Evidence

High

Microsoft

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

100
Noisy-finding weight
x0.50
Publisher domain
microsoft.com
Trusted match
Store verification signal
Verified publisher
Verified
Extension portfolio
653
Portfolio

11 evidence rows available.

No Threats Detected

This extension passed all security checks

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality strong.

The Jupyter Notebook Renderers extension is a legitimate development tool with a large user base of 83,747,821 users. Its purpose is to render Jupyter Notebooks with various output formats such as plotly, vega, gif, png, svg, and jpeg. The extension's filesystem and process access are justified by its stated purpose, as it needs to read and write files to render the notebooks. The network call detected in extension/out/client_renderer/preload.js:857 is likely a fetch call to retrieve necessary resources for rendering. The dependency findings, such as DEP-@vscode/jupyter-ipywidgets8 and DEP-vega, are expected as the extension relies on these dependencies to function. There are no credential-access findings targeting real secrets, and the strongest counterargument to this verdict is that the extension has a large number of dependencies, which could potentially introduce security risks. However, the dependencies are legitimate and necessary for the extension's functionality. The extension is from a verified publisher, ms-toolsai, which adds to its credibility.

Key Reasons

  • The extension's purpose justifies its filesystem and process access.
  • The network call detected is likely a necessary fetch call.
  • The dependencies are legitimate and necessary for the extension's functionality.

Reviewed 2026-05-23; recommended action: no action; model confidence 90%.

About This Extension

Renderers for Jupyter Notebooks (with plotly, vega, gif, png, svg, jpeg and other such outputs)

Frequently Asked Questions