OpenVSX Registry Verified

Composer

91b5dfb6-3b86-5525-9468-02d3eaa66bde | v1.74.19317
31/ 100
LOW risk
-18 since v1.74.19252
49 → 31 · false positives removed
Analyst verdict
No high-risk signal observed

Based on the RiskyPlugins AI security review of the observed evidence.

Analysis record

Analysed
1 weeks ago
Version
v1.74.19317
Artifact
SHA256 2F4…907
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

17 detail rows

Publisher Evidence

Low

devsense

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

55
Noisy-finding weight
x1.00
Publisher domain
No domain
Missing
Store verification signal
Verified publisher
Verified
Extension portfolio
4
Portfolio

12 evidence rows available.

Finding Categories

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality strong.

The Composer extension by devsense is a PHP Composer integration tool for VS Code. All 18 findings in this analysis are dependency declarations found in /tmp/extract-e988f7733da3ce4e10cc952abd1af0229054ad764d0f8fb9da5ed82d3269be23-3634258826/extension/package.json, including DEP-applicationinsights-^1.8.10, DEP-http-proxy-agent-^2.1.0, DEP-recursive-readdir-sync-^1.0.6, and DEP-node-rsa-^1.0.7. These are standard npm packages required for the extension's functionality.

The extension's filesystem and process access is fully justified by its stated purpose. A Composer integration tool must read and write composer.json files to provide IntelliSense, code lenses, and diagnostics. It must execute Composer commands via process spawning to install dependencies and run tasks. The DEP-recursive-readdir-sync-^1.0.6 dependency enables scanning project directories for Composer-related files, while DEP-http-proxy-agent-^2.1.0 and DEP-https-proxy-agent-^2.2.4 support proxy configuration for package downloads. These capabilities align exactly with the extension's description of providing "automatic installation, tasks, code lenses, diagnostics, and composer.json IntelliSense."

No credential-access findings target actual secrets. The findings summary shows zero secret findings ("secret":0). While DEP-node-rsa-^1.0.7 appears in the dependency list, this library is used for cryptographic operations within Composer's package signature verification, not for accessing developer credentials. There are no findings indicating reads of .env files, .git/config, SSH keys, or cloud credentials. The DEP-applicationinsights-^1.8.10 dependency is Microsoft's Application Insights SDK, used for legitimate telemetry collection via VS Code's telemetry API, not credential harvesting.

The strongest counterargument is that 18 findings might indicate hidden malicious behavior. This doesn't change the conclusion because all 18 findings are explicitly categorized as finding_type: "dependency" with severity: "low", representing normal package.json declarations. The threat_indicators show zero across all security-relevant categories: "ioc":"0","malware-signature":"0","malware":"0","network":"0","obfuscation":"0","tool-poisoning":"0". With nearly 30 million users and a verified publisher (devsense), this is an established, trusted extension. The findings represent build-time metadata, not runtime security concerns.

Key Reasons

  • All 18 findings are dependency declarations in package.json, not security issues
  • Zero IOC, malware, network, obfuscation, or secret findings
  • Extension capabilities align with stated Composer integration purpose
  • Nearly 30 million users indicates established, trusted extension
  • No credential access patterns or suspicious data collection

False Positive Considerations

  • Dependency findings are normal for Node.js extensions
  • All severity levels are low with no security-relevant categories triggered
  • Package.json declarations are expected build metadata
  • High user count correlates with legitimate, well-maintained extension

Reviewed 2026-05-23; recommended action: suppress false positive; model confidence 95%.

Open VSX version history

Risk trend by version

23 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
31
Change since first
No change
Change from previous
-18
Versions:
First analyzed version
1.68.18622
Mar 22, 2026
Risk range
31 to 49
Across analyzed versions
Latest analyzed version
1.74.19317
Sep 19, 2026
Selected version
low
Version
v1.74.19317
1 weeks ago
Risk score
31
Findings
17
Change vs previous
-18

Pick any point on the chart to explore that version's code below.

About This Extension

All-in-One composer integration, quick actions, commands, automatic installation, tasks, code lenses, diagnostics, and composer.json IntelliSense.

Frequently Asked Questions