Based on the RiskyPlugins AI security review of the observed evidence.
Analysis record
- Analysed
- 6 months ago
- Version
- v0.1.14
- Artifact
- SHA256 FAD…344
- Source
- Findings (non-IoC)
No Findings
All security checks passed
Publisher Evidence
LowShopify
Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
12 evidence rows available.
No Threats Detected
This extension passed all security checks
AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality strong.
This Shopify-published Ruby extension on OpenVSX (version 0.1.14, 9,900 users) was analyzed across all CVEQ detection modules — IoC extraction, malware signatures, manifest analysis, network behavior, obfuscation detection, dependency review, secret access patterns, code-smell heuristics, and tool-poisoning indicators. Every category returned zero findings, including zero code-smell hits, zero IoC matches, and zero YARA rule triggers. This is notable because even legitimate extensions typically generate noise from bundled dependencies, minified JavaScript, or basic Node.js patterns in postinstall hooks. The complete absence of findings indicates either a very lightweight package or one that avoids common patterns that trigger heuristic rules. Shopify is a well-known, established developer with a strong reputation, and this extension is an opinionated extension pack for Ruby development. The OpenVSX publishing channel is a legitimate mirror ecosystem. The one caveat is the OpenVSX store itself — while it mirrors official extensions, it can also host re-uploads. However, the combination of a recognized publisher name (Shopify), substantial install base (9,900 users), version history (0.1.14 suggests iterative development), and zero findings across all categories makes supply-chain tampering unlikely. There is no evidence of credential harvesting (zero secret findings), no network exfiltration indicators (zero network and IoC findings), no suspicious postinstall behavior (zero malware and code-smell findings), and no obfuscation techniques employed (zero obfuscation findings). The level of evidentiary support is limited in the sense that having zero findings provides no positive signal to evaluate — but the absence of any negative signal across nine distinct detection categories is itself informative for a non-trivial extension with nearly 10,000 users from a known publisher.
Key Reasons
- Zero findings across all nine detection categories including IoC, malware, obfuscation, and secret access
- Published by Shopify, a well-established and recognizable developer
- Substantial user base of approximately 9,900 installs suggesting community trust
- Iterative versioning (0.1.14) indicating active, legitimate development
Reviewed 2026-05-23; recommended action: no action; model confidence 85%.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace