Is "Saropa Log Capture" on OpenVSX Registry Safe to Install?

Verified
saropa · openvsx · v7.1.0

Automatically capture VS Code Debug Console output to persistent log files

Risk Assessment

Analyzed
31.18
out of 100
LOW

3 security findings detected across all analyzers

Open VSX extension analyzed via package manifest and static code analysis

Severity Breakdown

0
Critical
0
High
0
Medium
3
Low
0
Info

Finding Categories

About This Extension

Automatically capture VS Code Debug Console output to persistent log files

Detailed Findings

3 total

Security Analysis Summary

Security Analysis Overview

Saropa Log Capture is a OpenVSX Registry extension published by saropa. Version 7.1.0 has been analyzed by the Risky Plugins security platform, receiving a risk score of 31.18/100 (LOW risk) based on 3 security findings.

Risk Assessment

This extension presents low security risk. Some minor findings were detected, but nothing that would prevent typical usage. Reviewing the detailed findings below is recommended before use in sensitive environments.

Findings Breakdown

  • Low: 3 finding(s)

What Was Analyzed

The security assessment covers multiple analysis categories:

  • Malware Detection: YARA rule matching against 2,400+ malware signatures
  • Secret Detection: Scanning for exposed API keys, tokens, and credentials
  • Static Analysis: Code-level security analysis for common vulnerability patterns
  • Network Analysis: Detection of suspicious network communications and endpoints
  • Obfuscation Detection: Identification of code obfuscation techniques

Developer Information

Saropa Log Capture is published by saropa on the OpenVSX Registry marketplace.

Recommendation

Exercise caution with this extension. Review the detailed findings and ensure the requested permissions align with the extension's stated functionality before installation.

Frequently Asked Questions