VS Code Marketplace

Live Server

by Ritwick Dey · 82.8M users · 4.4 rating
0ac83b8a-b0c3-53b5-a193-03274a034694 | v5.7.10
56/ 100
MEDIUM risk
Analyst verdict
Review before use

The AI review rates the findings as likely false positive, but the risk score (56/100) still counts them.

Analysis record

Analysed
6 months ago
Version
v5.7.10
Artifact
SHA256 0F8…B95
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

22 detail rows

YARA Rule Matches

6 rules
SeverityRuleHitsFilesMetadata
HIGHDebuggerStatementsShouldNotBeUsed

The debugger statement can be placed anywhere in procedures to suspend execution. Using the debugger statement is similar to setting a breakpoint in the code. By definition such statement must absolutely be removed from the source code to prevent any unexpected behavior or added vulnerability to attacks in production. For more information checkout the CWE-489 (https://cwe.mitre.org/data/definitions/489.html) advisory.

1
README.md
FP 10%
HIGHpostinstall file download

File download activity detected

1
out/src/appModel.js
Risky Plugins Authors FP 30%
HIGHpostinstall network communication

Network communication detected

4
out/src/LiveServerHelper.jsLICENSE.txtCHANGELOG.md +1 more
Risky Plugins Authors FP 30%
HIGHpostinstall file manipulation

File system manipulation detected

1
CHANGELOG.md
Risky Plugins Authors FP 20%
HIGHpostinstall persistence mechanism

Persistence mechanism detected

1
package.json
Risky Plugins Authors FP 20%
HIGHpostinstall system command

System command execution detected

5
package.jsonout/src/Config.jsout/src/appModel.js +2 more
Risky Plugins Authors FP 10%

Publisher Evidence

Limited evidence

Ritwick Dey

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

50
Noisy-finding weight
x1.00
Publisher domain
No domain
Missing
Store verification signal
Not exposed
Not exposed
Extension portfolio
2
Portfolio

13 evidence rows available.

Finding Categories

13
Malware Signatures
4
Network

YARA Rules Matched

6 rules(13 hits)
DebuggerStatementsShouldNotBeUsed postinstall file download postinstall network communication postinstall file manipulation postinstall persistence mechanism postinstall system command

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality moderate.

The Live Server extension has several findings that warrant examination. The extension's purpose is to launch a development local server with live reload feature for static and dynamic pages. The filesystem and process access seem justified by the extension's stated purpose, as it needs to read and write files to serve them and execute processes to launch the server. However, there are some network findings, such as NET-SOCKET_IO and NET-FETCH, which could be related to the extension's functionality. The strongest counterargument to a malicious verdict is that the extension is from a verified publisher and has a large user base. The YARA rule matches, such as -DebuggerStatementsShouldNotBeUsed, -postinstall_network_communication, and -postinstall_system_command, are likely false positives, as they are common patterns in JavaScript code. The extension's dependencies, such as http-shutdown, ips, live-server-file, opn, and vsls, are all related to its functionality and do not seem suspicious. In conclusion, while there are some findings that could be concerning, they are likely related to the extension's legitimate functionality, and the extension's reputation and user base suggest that it is not malicious.

Key Reasons

  • justified filesystem and process access
  • verified publisher and large user base
  • likely false positive YARA rule matches

False Positive Considerations

  • YARA rule matches
  • network findings

Reviewed 2026-05-23; recommended action: no action; model confidence 80%.

About This Extension

Launch a development local Server with live reload feature for static & dynamic pages

Frequently Asked Questions