Firebase SQL Connect
The AI review rates the findings as likely false positive, but the risk score (44/100) still counts them.
Analysis record
- Analysed
- 2 weeks ago
- Version
- v2.4.3
- Artifact
- SHA256 3D3…42D
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
Publisher Evidence
HighGoogle Cloud
Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
11 evidence rows available.
Finding Categories
AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality strong.
The extension reads and writes files only as part of its advertised purpose of connecting VS Code to Firebase SQL; the only process‑related finding is the bundled language‑server client (vscode-languageclient) which is required to power code‑completion and is typical for this kind of tool. No post‑install script or child‑process execution was detected. The sole network finding, "NET-AXIOS-extension/dist/templates/extensions/javascript/integration-test.js-1", originates from an integration‑test script inside the dist/templates folder, which is used solely for internal testing and does not transmit workspace data. No secret‑access findings were reported – the secret category is empty, indicating the extension does not read .env, .ssh, or cloud credential files. The strongest counterargument would be that any outbound HTTP request might be used to exfiltrate data, but because the request resides in a test file, references only static URLs, and no payload construction or file‑content inclusion is present, the risk of malicious exfiltration is negligible.
Key Reasons
- Only low‑severity dependencies detected
- Network call present only in test script
- No credential‑access findings
- No post‑install or exec patterns
- Extension published by verified GoogleCloudTools publisher
False Positive Considerations
- network call in test file
- bundled dependency noise
- code‑smell YARA rules ignored
Reviewed 2026-05-23; recommended action: no action; model confidence 85%.
VS Code version history
Risk trend by version
10 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace