Based on the RiskyPlugins AI security review of the observed evidence.
Analysis record
- Analysed
- 1 weeks ago
- Version
- v1.74.19317
- Artifact
- SHA256 2F4…907
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
Publisher Evidence
Lowdevsense
Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
12 evidence rows available.
Finding Categories
AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality strong.
The Composer extension by devsense is a PHP Composer integration tool for VS Code. All 18 findings in this analysis are dependency declarations found in /tmp/extract-e988f7733da3ce4e10cc952abd1af0229054ad764d0f8fb9da5ed82d3269be23-3634258826/extension/package.json, including DEP-applicationinsights-^1.8.10, DEP-http-proxy-agent-^2.1.0, DEP-recursive-readdir-sync-^1.0.6, and DEP-node-rsa-^1.0.7. These are standard npm packages required for the extension's functionality.
The extension's filesystem and process access is fully justified by its stated purpose. A Composer integration tool must read and write composer.json files to provide IntelliSense, code lenses, and diagnostics. It must execute Composer commands via process spawning to install dependencies and run tasks. The DEP-recursive-readdir-sync-^1.0.6 dependency enables scanning project directories for Composer-related files, while DEP-http-proxy-agent-^2.1.0 and DEP-https-proxy-agent-^2.2.4 support proxy configuration for package downloads. These capabilities align exactly with the extension's description of providing "automatic installation, tasks, code lenses, diagnostics, and composer.json IntelliSense."
No credential-access findings target actual secrets. The findings summary shows zero secret findings ("secret":0). While DEP-node-rsa-^1.0.7 appears in the dependency list, this library is used for cryptographic operations within Composer's package signature verification, not for accessing developer credentials. There are no findings indicating reads of .env files, .git/config, SSH keys, or cloud credentials. The DEP-applicationinsights-^1.8.10 dependency is Microsoft's Application Insights SDK, used for legitimate telemetry collection via VS Code's telemetry API, not credential harvesting.
The strongest counterargument is that 18 findings might indicate hidden malicious behavior. This doesn't change the conclusion because all 18 findings are explicitly categorized as finding_type: "dependency" with severity: "low", representing normal package.json declarations. The threat_indicators show zero across all security-relevant categories: "ioc":"0","malware-signature":"0","malware":"0","network":"0","obfuscation":"0","tool-poisoning":"0". With nearly 30 million users and a verified publisher (devsense), this is an established, trusted extension. The findings represent build-time metadata, not runtime security concerns.
Key Reasons
- All 18 findings are dependency declarations in package.json, not security issues
- Zero IOC, malware, network, obfuscation, or secret findings
- Extension capabilities align with stated Composer integration purpose
- Nearly 30 million users indicates established, trusted extension
- No credential access patterns or suspicious data collection
False Positive Considerations
- Dependency findings are normal for Node.js extensions
- All severity levels are low with no security-relevant categories triggered
- Package.json declarations are expected build metadata
- High user count correlates with legitimate, well-maintained extension
Reviewed 2026-05-23; recommended action: suppress false positive; model confidence 95%.
Open VSX version history
Risk trend by version
23 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace