OpenVSX Registry Verified

Pyrefly - Python Language Tooling

by meta
1d324545-703a-5c1b-8b0d-897e0a1a01ae | v1.3.9001
31/ 100
LOW risk
-18 since v1.3.0
49 → 31 · false positives removed
Analyst verdict
No high-risk signal observed

Based on the RiskyPlugins AI security review of the observed evidence.

Analysis record

Analysed
5 days ago
Version
v1.3.9001
Artifact
SHA256 BCA…8F8
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

6 detail rows

Publisher Evidence

Low

meta

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

50
Noisy-finding weight
x1.00
Publisher domain
No domain
Missing
Store verification signal
Verified publisher
Verified
Extension portfolio
1
Portfolio

13 evidence rows available.

Finding Categories

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality strong.

The Pyrefly - Python Language Tooling extension shows no security concerns in the analysis. All six findings are dependency declarations listed in /tmp/extract-cca9736935d43b774db3c342a667a773fb5be0406af540ca087bfaaa88978b12-3442691157/extension/package.json, which is normal for any VS Code extension. The dependencies include [email protected], @vscode/python-environments@^1.0.0, and @vscode/python-extension@^1.0.5 — these are standard Microsoft VS Code Python extension packages used for language server communication and environment detection. The remaining dependencies (serialize-javascript@^7.0.5, underscore@^1.13.8, vsce@^2.15.0) are common build and utility libraries.

This extension has zero findings for credential access, network calls, obfuscation, or malware signatures. There are no findings targeting .env files, SSH keys, cloud credentials, or VS Code secret storage. The extension's stated purpose is Python autocomplete and typechecking via a language server, which legitimately requires file reading for code analysis and process spawning for the language server itself. However, the analysis found no evidence of these behaviors — only package.json dependency declarations.

The strongest counterargument to this verdict would be the high user count (61 million) combined with the developer name "meta" raising questions about whether this is an official Microsoft extension or a third-party re-upload. However, the OpenVSX store hosts both official and community extensions, and the dependency list matches legitimate VS Code Python tooling patterns. The absence of any suspicious findings (IoC, malware, credential access, obfuscation) across all categories confirms this is a standard language server extension with normal build artifacts. The extension performs expected IDE behaviors for Python development without exhibiting malicious patterns like postinstall payload execution, workspace exfiltration, or credential theft.

Key Reasons

  • Zero malware, IoC, or credential findings
  • All findings are standard VS Code Python extension dependencies
  • No suspicious filesystem or network behavior detected
  • Dependency list matches legitimate language server patterns

False Positive Considerations

  • Dependency scanning flags legitimate npm packages
  • Standard VS Code Python extension dependencies
  • No actual security findings beyond package.json declarations

Reviewed 2026-05-23; recommended action: no action; model confidence 95%.

Open VSX version history

Risk trend by version

17 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
31
Change since first
-39
Change from previous
-18
Versions:
First analyzed version
0.57.1
Mar 22, 2026
Risk range
31 to 70
Across analyzed versions
Latest analyzed version
1.3.9001
Sep 19, 2026
Selected version
low
Version
v1.3.9001
1 weeks ago
Risk score
31
Findings
6
Change vs previous
-18

Pick any point on the chart to explore that version's code below.

About This Extension

Python autocomplete, typechecking, code navigation and more! Powered by Pyrefly, an open-source language server

Frequently Asked Questions