VS Code Marketplace

Snapline — Code Screenshots

by branchline. · 1 downloads
8c207aaf-039a-5d3d-88c7-c1f3663927c0 | v0.1.0
46/ 100
MEDIUM risk
Analyst verdict
Review before use

The AI review rates the findings as likely false positive, but the risk score (46/100) still counts them.

Analysis record

Analysed
2 days ago
Version
v0.1.0
Artifact
SHA256 5EE…AD4
Source
Findings (non-IoC)

Is Snapline — Code Screenshots safe?

Snapline takes your source code and turns it into shareable images using your editor theme. To render those images, it reads the files in your workspace. The extension does not request any special host permissions in its manifest. The only external network connections it makes go to api.gumroad.com and dealership6.gumroad.com, which are standard endpoints used by independent developers to verify paid software licenses.

Scanners flagged a finding titled YARA--credential_env_files inside the dist/extension.js and dist/webview.js files. If this finding were accurate, it would mean the extension is secretly reading your environment files or stealing API keys. The scanners also flagged postinstall file downloads, which usually points to malicious payloads being fetched during setup.

Those findings are scanner noise. The credential finding tripped on minified JavaScript code bundled in the dist folder, where random variable names accidentally matched a generic rule about environment files. The download alerts triggered on standard network calls used to check your license key against the Gumroad commerce platform. Other network alerts were just the scanner misreading JavaScript property chains like e.target.dataset.bg as actual web domains. The extension only reads your files to render them and contacts Gumroad to verify your license.

No Findings

All security checks passed

Publisher Evidence

Limited evidence

branchline.

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

39
Noisy-finding weight
x1.00
Publisher domain
No domain
Missing
Store verification signal
Not exposed
Not exposed
Extension portfolio
5
Portfolio

13 evidence rows available.

No Threats Detected

This extension passed all security checks

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality strong.

The Snapline extension generates images from source code. To do this, it reads workspace files and renders them in a webview. This filesystem access is entirely consistent with its stated purpose. The extension declares no special host permissions in its manifest, and there are no findings indicating it spawns arbitrary processes or executes shell commands. Its operational footprint is limited to reading text files and drawing them, which is exactly what a screenshot tool needs to do.

Security scanners flagged YARA--credential_env_files in both dist/extension.js and dist/webview.js. If this were a real credential theft operation, we would expect to see the extension reading .env files, .ssh directories, or cloud provider tokens. Instead, these are low-severity code-smell matches. The YARA rule triggered on minified JavaScript bundled in the dist/ directory. This is a well-documented false positive pattern where standard variable names or string literals in minified code accidentally match credential-related keywords. There are zero secret-extraction findings and no evidence of the extension accessing VS Code secret storage or attempting to harvest developer credentials.

The strongest argument against this extension is the presence of YARA--postinstall_file_download in the bundled files and network connections to dealership6.gumroad.com and api.gumroad.com. A skeptic might argue these indicate a malicious payload downloading additional code or exfiltrating data to a remote server. The extracted URLs show standard commerce traffic. The network endpoints include https://api.gumroad.com/v2/licenses/verify and https://dealership6.gumroad.com/l/branchline-pro. Gumroad is a standard digital commerce platform used by independent developers to sell software licenses. The extension is simply verifying a paid pro license key. The postinstall_file_download YARA rule matched basic fetch or https calls within the minified dist/ files, which is expected behavior for an extension that needs to verify a license against a remote commerce server.

Furthermore, the XIOC extractor misidentified several JavaScript property access chains as network domains. Findings like XIOC-DOMAIN-e.target.dataset.bg, XIOC-DOMAIN-r.dataset.bg, and XIOC-DOMAIN-month.abb are clearly fragments of minified DOM manipulation or date formatting code, not actual DNS requests. The only other network endpoint, schemas.openxmlformats.org, is a standard XML namespace URL likely pulled in by a bundled image-generation or document-parsing library. With zero malware signatures, no actual credential theft, and all network traffic tied to legitimate license verification or misidentified JavaScript syntax, the findings are entirely noise.

Key Reasons

  • IoC findings are property access chains (e.target.dataset.bg) and legitimate Gumroad license verification URLs
  • Code-smell YARA rules triggered on minified dist/ files, a known false positive pattern
  • No malware signatures, secrets, or suspicious postinstall execution found
  • Extension purpose aligns with standard file read access, and no excessive permissions are declared

False Positive Considerations

  • XIOC extractor misidentifying JS property chains (e.target.dataset.bg) as domains
  • YARA code-smell rules firing on bundled/minified dist/ files
  • Gumroad URLs flagged as IoCs despite being standard indie extension monetization/license verification

Reviewed 2026-10-01; recommended action: suppress false positive; model confidence 95%.

About This Extension

Turn code into beautiful, shareable images in one click — using your exact editor theme. A maintained alternative to CodeSnap and Polacode.

Frequently Asked Questions