Is "viiv" on VS Code Marketplace Safe to Install?

B.W · vscode · v1.0.7

A VsCode theme that puts developers into focus mode quickly.

Risk Assessment

Analyzed
40.22
out of 100
MEDIUM

1428 security findings detected across all analyzers

VS Code extension analyzed via package manifest and static code analysis

Severity Breakdown

0
Critical
1351
High
77
Medium
0
Low
0
Info

Finding Categories

1000
Malware Signatures

YARA Rules Matched

5 rules(1000 hits)
postinstall obfuscation postinstall system command postinstall file manipulation postinstall file download postinstall network communication

About This Extension

A VsCode theme that puts developers into focus mode quickly.

Detailed Findings

1000 total

YARA Rule Matches

5 rules

Security Analysis Summary

Security Analysis Overview

viiv is a Visual Studio Code Marketplace extension published by B.W. Version 1.0.7 has been analyzed by the Risky Plugins security platform, receiving a risk score of 40.22/100 (MEDIUM risk) based on 1428 security findings.

Risk Assessment

This extension presents moderate security risk. Several findings were detected that may warrant attention. Users should carefully review the permissions and findings before installation.

Findings Breakdown

  • High: 1351 finding(s)
  • Medium: 77 finding(s)

What Was Analyzed

The security assessment covers multiple analysis categories:

  • Malware Detection: YARA rule matching against 2,400+ malware signatures
  • Secret Detection: Scanning for exposed API keys, tokens, and credentials
  • Static Analysis: Code-level security analysis for common vulnerability patterns
  • Network Analysis: Detection of suspicious network communications and endpoints
  • Obfuscation Detection: Identification of code obfuscation techniques

Developer Information

viiv is published by B.W on the Visual Studio Code Marketplace marketplace. The extension has approximately 253 users.

Recommendation

Exercise caution with this extension. Review the detailed findings and ensure the requested permissions align with the extension's stated functionality before installation.

Frequently Asked Questions