VS Code Marketplace Verified

Firebase SQL Connect

by Google Cloud · 49.8K users · 5.0 rating
17131ca4-5797-51f2-95d1-2cae7a16d792 | v2.4.3
44/ 100
MEDIUM risk
No change since v2.4.2
Analyst verdict
Review before use

The AI review rates the findings as likely false positive, but the risk score (44/100) still counts them.

Analysis record

Analysed
2 weeks ago
Version
v2.4.3
Artifact
SHA256 3D3…42D
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

14 detail rows

Publisher Evidence

High

Google Cloud

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

100
Noisy-finding weight
x0.50
Publisher domain
google.com
Trusted match
Store verification signal
Verified publisher
Verified
Extension portfolio
557
Portfolio

11 evidence rows available.

Finding Categories

1
Network

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality strong.

The extension reads and writes files only as part of its advertised purpose of connecting VS Code to Firebase SQL; the only process‑related finding is the bundled language‑server client (vscode-languageclient) which is required to power code‑completion and is typical for this kind of tool. No post‑install script or child‑process execution was detected. The sole network finding, "NET-AXIOS-extension/dist/templates/extensions/javascript/integration-test.js-1", originates from an integration‑test script inside the dist/templates folder, which is used solely for internal testing and does not transmit workspace data. No secret‑access findings were reported – the secret category is empty, indicating the extension does not read .env, .ssh, or cloud credential files. The strongest counterargument would be that any outbound HTTP request might be used to exfiltrate data, but because the request resides in a test file, references only static URLs, and no payload construction or file‑content inclusion is present, the risk of malicious exfiltration is negligible.

Key Reasons

  • Only low‑severity dependencies detected
  • Network call present only in test script
  • No credential‑access findings
  • No post‑install or exec patterns
  • Extension published by verified GoogleCloudTools publisher

False Positive Considerations

  • network call in test file
  • bundled dependency noise
  • code‑smell YARA rules ignored

Reviewed 2026-05-23; recommended action: no action; model confidence 85%.

VS Code version history

Risk trend by version

10 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
44
Change since first
-13
Change from previous
No change
Versions:
First analyzed version
2.0.1
Jan 23, 2026
Risk range
44 to 56
Across analyzed versions
Latest analyzed version
2.4.3
Jul 24, 2026
Selected version
medium
Version
v2.4.3
2 months ago
Risk score
44
Findings
14
Change vs previous
No change

Pick any point on the chart to explore that version's code below.

About This Extension

Firebase SQL Connect for VSCode

Frequently Asked Questions