Is "WindMillCode Extension Pack Zero" on VS Code Marketplace Safe to Install?

windmillcode · vscode · v1.85.1000

Big extension pack of useful extensions

Risk Assessment

Analyzed
63.05
out of 100
MEDIUM

7922 security findings detected across all analyzers

Severity Breakdown

0
Critical
1869
High
6047
Medium
6
Low
0
Info

Finding Categories

1000
Malware

YARA Rules Matched

19 rules(1000 hits)
postinstall network communication credential env files postinstall system command postinstall file manipulation postinstall obfuscation postinstall crypto operations UsingShellInterpreterWhenExecutingOSCommands postinstall file download postinstall registry modification postinstall persistence mechanism NoDisableSanitizeHtml NoUseWeakRandom UsingCommandLineArguments postinstall environment access DebuggerStatementsShouldNotBeUsed NoUseEval +3 more

About This Extension

Big extension pack of useful extensions

Detailed Findings

1000 total

YARA Rule Matches

19 rules

Security Analysis Summary

Security Analysis Overview

WindMillCode Extension Pack Zero is a Visual Studio Code Marketplace extension published by windmillcode. Version 1.85.1000 has been analyzed by the Risky Plugins security platform, receiving a risk score of 63.05/100 (MEDIUM risk) based on 7922 security findings.

Risk Assessment

This extension presents high security risk. Significant concerns were identified during analysis. It is not recommended for use in sensitive or production environments without thorough review.

Findings Breakdown

  • High: 1869 finding(s)
  • Medium: 6047 finding(s)
  • Low: 6 finding(s)

What Was Analyzed

The security assessment covers multiple analysis categories:

  • Malware Detection: YARA rule matching against 2,400+ malware signatures
  • Secret Detection: Scanning for exposed API keys, tokens, and credentials
  • Static Analysis: Code-level security analysis for common vulnerability patterns
  • Network Analysis: Detection of suspicious network communications and endpoints
  • Obfuscation Detection: Identification of code obfuscation techniques

Developer Information

WindMillCode Extension Pack Zero is published by windmillcode on the Visual Studio Code Marketplace marketplace. The extension has approximately 4 users.

Recommendation

This extension is not recommended for installation without thorough manual review. Consider alternatives with lower risk scores, or contact the developer to address the identified security concerns.

Frequently Asked Questions