OpenVSX Registry Verified

PostgreSQL

0fe1bbda-ac54-5f4b-a3f5-b3259f75c612 | v1.30.1
49/ 100
MEDIUM risk
No change since v1.29.1
Analyst verdict
Review before use

The AI review rates the findings as likely false positive, but the risk score (49/100) still counts them.

Analysis record

Analysed
3 weeks ago
Version
v1.30.1
Artifact
SHA256 D44…C3D
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

6 detail rows

Publisher Evidence

Low

microsoft

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

50
Noisy-finding weight
x1.00
Publisher domain
No domain
Missing
Store verification signal
Verified publisher
Verified
Extension portfolio
1
Portfolio

13 evidence rows available.

Finding Categories

5
Network

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality strong.

The PostgreSQL extension ships a sizable node_modules tree that includes common libraries such as axios, jquery, d3, and several @azure packages. The scanner flagged dozens of network‑call findings – for example, NET-XMLHTTPREQUEST-extension/node_modules/jquery/dist/jquery.js:9800, NET-AXIOS-extension/node_modules/axios/lib/axios.js:70, and NET-FETCH-extension/node_modules/d3/dist/d3.js:8329. These are standard HTTP client calls made by the bundled libraries to fetch resources (e.g., CDN assets, Azure telemetry) and are unrelated to the extension’s core purpose of helping developers write PostgreSQL applications. No file‑system or process‑spawning findings were reported, and there are no post‑install scripts, child_process.exec calls, or similar activation‑time code. Consequently, the extension’s filesystem and process access is fully justified by its stated purpose of providing language‑service, linting, and scaffolding capabilities for PostgreSQL projects.

The evidence contains zero secret‑access findings – no references to .env, .git/config, SSH keys, cloud credential files, or VS Code secret‑storage APIs. The “secret” category count is reported as 0, confirming that the extension does not attempt to read or exfiltrate credential material. All network activity originates from generic libraries rather than custom code aimed at transmitting file contents.

A possible counterargument is the sheer volume of reported items – the summary lists 25,508 IoC entries and 89 network findings, which might suggest suspicious outbound communication. However, the majority of those IoC entries are generic strings (e.g., domain fragments, IPv4/IPv6 placeholders) that the CVEQ IoC extractor frequently mislabels in minified bundle code. The extension’s package is dominated by bundled dependencies, and the scanner’s own documentation classifies such bulk matches as false positives. Moreover, the network calls are all tied to well‑known, reputable libraries (axios, jquery, d3, @azure/*) that are used by countless legitimate extensions. Therefore, the high count does not change the conclusion that the behavior is benign and expected for a development tool.

In summary, the only findings of note are standard library network requests, and there is no evidence of credential theft, post‑install payload execution, or supply‑chain poisoning. The extension’s permissions align with its functionality, and the apparent threats are artifacts of bundled code and noisy IoC extraction.

Key Reasons

  • All network calls belong to bundled libraries (axios, jquery, d3, @azure) used for legitimate functionality
  • No credential‑access findings were detected
  • No post‑install or process‑execution code was found
  • High IoC count is explained by bundled dependencies and known extractor noise

False Positive Considerations

  • Bundled dependencies generating many library‑level findings
  • IoC extractor garbage (generic strings, domain fragments)
  • Code‑smell YARA rules (not present but typical noise source)
  • High finding count from minified bundle files

Reviewed 2026-05-28; recommended action: no action; model confidence 92%.

Open VSX version history

Risk trend by version

10 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
49
Change since first
-3
Change from previous
No change
Versions:
First analyzed version
1.23.5
May 26, 2026
Risk range
49 to 51
Across analyzed versions
Latest analyzed version
1.30.1
Sep 5, 2026
Selected version
medium
Version
v1.30.1
3 weeks ago
Risk score
49
Findings
6
Change vs previous
No change

Pick any point on the chart to explore that version's code below.

About This Extension

Develop, query, and manage PostgreSQL (Postgres) databases with IntelliSense, Object Explorer, schema tools, and AI-assisted workflows.

Frequently Asked Questions