OpenVSX Registry Verified

Ruby

82b41cd4-ac45-57e9-97d0-562d78a34861 | v0.1.14
0/ 100
MINIMAL risk
Analyst verdict
No high-risk signal observed

Based on the RiskyPlugins AI security review of the observed evidence.

Analysis record

Analysed
6 months ago
Version
v0.1.14
Artifact
SHA256 FAD…344
Source
Findings (non-IoC)

No Findings

All security checks passed

Publisher Evidence

Low

Shopify

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

55
Noisy-finding weight
x1.00
Publisher domain
No domain
Missing
Store verification signal
Verified publisher
Verified
Extension portfolio
3
Portfolio

12 evidence rows available.

No Threats Detected

This extension passed all security checks

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality strong.

This Shopify-published Ruby extension on OpenVSX (version 0.1.14, 9,900 users) was analyzed across all CVEQ detection modules — IoC extraction, malware signatures, manifest analysis, network behavior, obfuscation detection, dependency review, secret access patterns, code-smell heuristics, and tool-poisoning indicators. Every category returned zero findings, including zero code-smell hits, zero IoC matches, and zero YARA rule triggers. This is notable because even legitimate extensions typically generate noise from bundled dependencies, minified JavaScript, or basic Node.js patterns in postinstall hooks. The complete absence of findings indicates either a very lightweight package or one that avoids common patterns that trigger heuristic rules. Shopify is a well-known, established developer with a strong reputation, and this extension is an opinionated extension pack for Ruby development. The OpenVSX publishing channel is a legitimate mirror ecosystem. The one caveat is the OpenVSX store itself — while it mirrors official extensions, it can also host re-uploads. However, the combination of a recognized publisher name (Shopify), substantial install base (9,900 users), version history (0.1.14 suggests iterative development), and zero findings across all categories makes supply-chain tampering unlikely. There is no evidence of credential harvesting (zero secret findings), no network exfiltration indicators (zero network and IoC findings), no suspicious postinstall behavior (zero malware and code-smell findings), and no obfuscation techniques employed (zero obfuscation findings). The level of evidentiary support is limited in the sense that having zero findings provides no positive signal to evaluate — but the absence of any negative signal across nine distinct detection categories is itself informative for a non-trivial extension with nearly 10,000 users from a known publisher.

Key Reasons

  • Zero findings across all nine detection categories including IoC, malware, obfuscation, and secret access
  • Published by Shopify, a well-established and recognizable developer
  • Substantial user base of approximately 9,900 installs suggesting community trust
  • Iterative versioning (0.1.14) indicating active, legitimate development

Reviewed 2026-05-23; recommended action: no action; model confidence 85%.

About This Extension

An opinionated and auto-configured set of extensions for Ruby development

Frequently Asked Questions