VS Code Marketplace Verified

Python

by Microsoft · 238.6M users · 4.2 rating
34da9bbf-5bfd-5596-8a12-7da25be4e269 | v2026.7.2026092501
31/ 100
LOW risk
No change since v2026.7.2026091701
Risk verdict
No high-risk signal observed

Score-based assessment (low risk, 31/100). Last analyst review covers version 2026.5.2026051501.

No individual score drivers were recorded for this analysis.

Analysis record

Analysed
4 days ago
Version
v2026.7.2026092501
Artifact
SHA256 FE3…A29
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

29 detail rows
Showing 25 of 29 · highest severity first

Publisher Evidence

High

Microsoft

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

100
Noisy-finding weight
x0.50
Publisher domain
microsoft.com
Trusted match
Store verification signal
Verified publisher
Verified
Extension portfolio
653
Portfolio

11 evidence rows available.

Finding Categories

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality strong.

The Python extension for VS Code provides language support with various features such as IntelliSense, debugging, linting, formatting, and more. The extension's dependencies include iconv-lite, jsonc-parser, semver, arch, vscode-tas-client, sudo-prompt, stack-trace, winreg, @vscode/extension-telemetry, which, vscode-languageclient, and vscode-languageserver-protocol. These dependencies are typical for a language support extension and are used for tasks such as parsing, formatting, and communicating with the language server. The extension does not have any findings related to malware signatures, IOCs, or obfuscation. The @vscode/extension-telemetry dependency is used for sending telemetry data to the VS Code team, which is a standard practice for many extensions. The sudo-prompt dependency is used for prompting the user for sudo access when necessary, which is a legitimate use case for some features of the extension. Overall, the extension's dependencies and features are consistent with its stated purpose and do not indicate any malicious behavior. The strongest counterargument to this verdict would be that some of the dependencies could potentially be used for malicious purposes, but there is no evidence to suggest that this is the case. The extension is from a verified publisher on the VS Code marketplace, which adds to its credibility. In conclusion, the findings in the evidence bundle do not suggest any malicious behavior, and the extension's dependencies and features are consistent with its stated purpose.

Key Reasons

  • The extension's dependencies are typical for a language support extension.
  • There are no findings related to malware signatures, IOCs, or obfuscation.
  • The extension is from a verified publisher on the VS Code marketplace.

Reviewed 2026-05-23; recommended action: no action; model confidence 90%.

VS Code version history

Risk trend by version

12 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
31
Change since first
-10
Change from previous
No change
Versions:
First analyzed version
2026.5.2026031201
Mar 14, 2026
Risk range
31 to 42
Across analyzed versions
Latest analyzed version
2026.7.2026092501
Sep 27, 2026
Selected version
low
Version
v2026.7.2026092501
4 days ago
Risk score
31
Findings
29
Change vs previous
No change

Pick any point on the chart to explore that version's code below.

About This Extension

Python language support with extension access points for IntelliSense (Pylance), Debugging (Python Debugger), linting, formatting, refactoring, unit tests, and more.

Frequently Asked Questions