The AI review rates the findings as likely false positive, but the risk score (49/100) still counts them.
Analysis record
- Analysed
- 3 weeks ago
- Version
- v1.30.1
- Artifact
- SHA256 D44…C3D
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
Publisher Evidence
Lowmicrosoft
Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
13 evidence rows available.
Finding Categories
AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality strong.
The PostgreSQL extension ships a sizable node_modules tree that includes common libraries such as axios, jquery, d3, and several @azure packages. The scanner flagged dozens of network‑call findings – for example, NET-XMLHTTPREQUEST-extension/node_modules/jquery/dist/jquery.js:9800, NET-AXIOS-extension/node_modules/axios/lib/axios.js:70, and NET-FETCH-extension/node_modules/d3/dist/d3.js:8329. These are standard HTTP client calls made by the bundled libraries to fetch resources (e.g., CDN assets, Azure telemetry) and are unrelated to the extension’s core purpose of helping developers write PostgreSQL applications. No file‑system or process‑spawning findings were reported, and there are no post‑install scripts, child_process.exec calls, or similar activation‑time code. Consequently, the extension’s filesystem and process access is fully justified by its stated purpose of providing language‑service, linting, and scaffolding capabilities for PostgreSQL projects.
The evidence contains zero secret‑access findings – no references to .env, .git/config, SSH keys, cloud credential files, or VS Code secret‑storage APIs. The “secret” category count is reported as 0, confirming that the extension does not attempt to read or exfiltrate credential material. All network activity originates from generic libraries rather than custom code aimed at transmitting file contents.
A possible counterargument is the sheer volume of reported items – the summary lists 25,508 IoC entries and 89 network findings, which might suggest suspicious outbound communication. However, the majority of those IoC entries are generic strings (e.g., domain fragments, IPv4/IPv6 placeholders) that the CVEQ IoC extractor frequently mislabels in minified bundle code. The extension’s package is dominated by bundled dependencies, and the scanner’s own documentation classifies such bulk matches as false positives. Moreover, the network calls are all tied to well‑known, reputable libraries (axios, jquery, d3, @azure/*) that are used by countless legitimate extensions. Therefore, the high count does not change the conclusion that the behavior is benign and expected for a development tool.
In summary, the only findings of note are standard library network requests, and there is no evidence of credential theft, post‑install payload execution, or supply‑chain poisoning. The extension’s permissions align with its functionality, and the apparent threats are artifacts of bundled code and noisy IoC extraction.
Key Reasons
- All network calls belong to bundled libraries (axios, jquery, d3, @azure) used for legitimate functionality
- No credential‑access findings were detected
- No post‑install or process‑execution code was found
- High IoC count is explained by bundled dependencies and known extractor noise
False Positive Considerations
- Bundled dependencies generating many library‑level findings
- IoC extractor garbage (generic strings, domain fragments)
- Code‑smell YARA rules (not present but typical noise source)
- High finding count from minified bundle files
Reviewed 2026-05-28; recommended action: no action; model confidence 92%.
Open VSX version history
Risk trend by version
10 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace