OpenVSX Registry Verified

Codex Translation Editor

758351ed-18b4-5b1e-9922-a2dc411872f0 | v0.34.0
50/ 100
MEDIUM risk
-18 since v0.33.0
68 → 50 · false positives removed
Analyst verdict
Review before use

The AI review rates the findings as likely false positive, but the risk score (50/100) still counts them.

Analysis record

Analysed
1 weeks ago
Version
v0.34.0
Artifact
SHA256 928…9F4
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

384 detail rows
Showing 25 of 49 · highest severity first

YARA Rule Matches

19 rules
SeverityRuleHitsFilesMetadata
LOWLocalStorageShouldNotBeUsed 10
webviews/codex-webviews/dist/MissingToolsWarning/index.js.mapwebviews/codex-webviews/dist/PublishProject/index.js.mapwebviews/codex-webviews/dist/StartupFlow/index.js.map +7 more
-
LOWpostinstall persistence mechanism 13
webviews/codex-webviews/dist/CellLabelImporterView/index.js.mapwebviews/codex-webviews/dist/StartupFlow/index.js.mapwebviews/codex-webviews/dist/StartupFlow/index.js +10 more
-
LOWcredential env files 19
webviews/codex-webviews/dist/PublishProject/index.js.mapwebviews/codex-webviews/dist/CommentsView/index.js.mapwebviews/codex-webviews/dist/StartupFlow/index.js.map +16 more
-
LOWcredential vscode credentials 2
out/extension.jspackage.json
-
LOWNoUseEval 1
out/extension.js
-
LOWNoUseWeakRandom 35
webviews/codex-webviews/dist/InterfaceSettings/index.jswebviews/codex-webviews/dist/CommentsView/index.js.mapwebviews/codex-webviews/dist/MissingToolsWarning/index.js.map +32 more
-
LOWpostinstall file download 36
webviews/codex-webviews/dist/MissingToolsWarning/index.js.mapwebviews/codex-webviews/dist/NewSourceUploader/index.jswebviews/codex-webviews/dist/AutomatedTesting/index.js +33 more
-
LOWcredential git credentials 1
out/extension.js
-
LOWUntrustedContentShouldNotBeIncluded 2
webviews/codex-webviews/dist/CodexCellEditor/index.jswebviews/codex-webviews/dist/CodexCellEditor/index.js.map
-
LOWUsingIntrusivePermissionsWithGeolocation 6
webviews/codex-webviews/dist/MissingToolsWarning/index.js.mapwebviews/codex-webviews/dist/EditableReactTable/index.js.mapwebviews/codex-webviews/dist/MainMenu/index.js.map +3 more
-
LOWSQLInjection 7
webviews/codex-webviews/dist/SystemMessageReview/index.jswebviews/codex-webviews/dist/StartupFlow/index.jswebviews/codex-webviews/dist/CodexCellEditor/index.js +4 more
-
LOWpostinstall file manipulation 35
webviews/codex-webviews/dist/SplashScreen/index.js.mapwebviews/codex-webviews/dist/MissingToolsWarning/index.js.mapwebviews/codex-webviews/dist/AutomatedTesting/index.js +32 more
-
LOWpostinstall crypto operations 36
webviews/codex-webviews/dist/AutomatedTesting/index.jswebviews/codex-webviews/dist/NavigationView/index.jswebviews/codex-webviews/dist/SplashScreen/index.js +33 more
-
LOWpostinstall system command 38
webviews/codex-webviews/dist/CopilotSettings/index.jsreadme.mdwebviews/codex-webviews/dist/CommentsView/index.js +35 more
-
LOWpostinstall registry modification 12
webviews/codex-webviews/dist/EditableReactTable/index.js.mapwebviews/codex-webviews/dist/CellLabelImporterView/index.js.mapwebviews/codex-webviews/dist/CellLabelImporterView/index.js +9 more
-
LOWpostinstall obfuscation 36
webviews/codex-webviews/dist/MissingToolsWarning/index.js.mapwebviews/codex-webviews/dist/NewSourceUploader/index.jswebviews/codex-webviews/dist/AutomatedTesting/index.js +33 more
-
LOWpostinstall network communication 34
webviews/codex-webviews/dist/MissingToolsWarning/index.js.mapwebviews/codex-webviews/dist/AutomatedTesting/index.jswebviews/codex-webviews/dist/NavigationView/index.js +31 more
-
LOWOriginsNotVerified 11
webviews/codex-webviews/dist/SystemMessageReview/index.jswebviews/codex-webviews/dist/SplashScreen/index.jswebviews/codex-webviews/dist/CommentsView/index.js +8 more
-
LOWUsingShellInterpreterWhenExecutingOSCommands 1
out/extension.js
-

Publisher Evidence

Low

project-accelerate

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

65
Noisy-finding weight
x1.00
Publisher domain
No domain
Missing
Store verification signal
Verified publisher
Verified
Extension portfolio
11
Portfolio

12 evidence rows available.

Finding Categories

1
Network

YARA Rules Matched

19 rules(335 hits)
LocalStorageShouldNotBeUsed postinstall persistence mechanism credential env files credential vscode credentials NoUseEval NoUseWeakRandom postinstall file download credential git credentials UntrustedContentShouldNotBeIncluded UsingIntrusivePermissionsWithGeolocation SQLInjection postinstall file manipulation postinstall crypto operations postinstall system command postinstall registry modification postinstall obfuscation +3 more

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality strong.

The Codex Translation Editor extension declares support for .codex notebooks and translation source files, which justifies its network behavior. The 48 network findings consist entirely of fetch calls in extension/out/4.extension.js:10236, extension/out/extension.js:9327, extension/out/extension.js:9521, extension/out/3.extension.js:23159, extension/out/1.extension.js:16830, extension/out/1.extension.js:1590, extension/out/4.extension.js:317, extension/out/4.extension.js:10307, extension/out/1.extension.js:12345, extension/out/3.extension.js:22769 and socket_io calls in extension/webviews/codex-webviews/dist/EditableReactTable/index.js:58 and extension/webviews/codex-webviews/dist/EditableReactTable/index.js:209. These are expected patterns for a translation editor that must communicate with translation APIs and render interactive webview components.

No credential-access findings were detected. The findings_summary shows secret:0 with no matches for .env files, .git/config, SSH keys, or cloud credentials. This is consistent with the extension's stated purpose, which does not require access to secrets.

The strongest counterargument is the volume of network calls (48 findings), which could theoretically indicate data exfiltration. However, the threat_indicators show ioc:0 and malware-signature:0, meaning none of these network calls target suspicious domains. The calls occur in bundled output files (extension/out/) and webview dist folders (extension/webviews/codex-webviews/dist/), which are standard locations for compiled extension code and third-party UI libraries. The 48 low-severity dependency findings are consistent with bundled npm packages, not malicious code.

With 62,522 users, no malware signatures, no obfuscation findings, and network behavior justified by translation functionality, this extension exhibits normal IDE extension patterns. The findings are false positives from expected network activity in a translation tool.

Key Reasons

  • Zero malware-signature and zero ioc findings
  • Network activity justified by translation editor purpose
  • No credential-access or secret findings
  • Webview socket_io calls are standard UI pattern

False Positive Considerations

  • Network calls in translation editor are expected behavior for API communication
  • socket_io in webview dist folder is standard UI component pattern
  • No IoC matches despite 48 network findings
  • Zero malware signatures and zero obfuscation findings

Reviewed 2026-05-23; recommended action: no action; model confidence 85%.

Open VSX version history

Risk trend by version

9 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
50
Change since first
-6
Change from previous
-18
Versions:
First analyzed version
0.25.0
Apr 18, 2026
Risk range
44 to 68
Across analyzed versions
Latest analyzed version
0.34.0
Sep 19, 2026
Selected version
medium
Version
v0.34.0
1 weeks ago
Risk score
50
Findings
384
Change vs previous
-18

Pick any point on the chart to explore that version's code below.

About This Extension

Support for `.codex` notebooks and translation source files.

Frequently Asked Questions