Composer
Based on the RiskyPlugins AI security review of the observed evidence.
Analysis record
- Analysed
- 6 days ago
- Version
- v1.74.19317
- Artifact
- SHA256 2F4…907
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
Publisher Evidence
LowDEVSENSE
Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
12 evidence rows available.
Finding Categories
AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality strong.
Composer is advertised as an All‑In‑One Composer integration that supplies quick actions, command registration, automatic installation assists, task management, code‑lens support, diagnostics, and composer.json IntelliSense. Because the extension operates inside the IDE, it must be able to read project files — especially composer.json — and may spawn Node processes to resolve npm packages. The investigation of the extension’s package.json at /tmp/extract-46a5fdc07371c6341ff4621b7ab809620466c018e027e1937f2b955c6d193b18-1534519640/extension/package.json shows that it declares eleven npm dependencies: xmldom@^0.6.0, file-url@^2.0.0, applicationinsights@^1.8.10, escape-string-regexp@^1.0.5, http-proxy-agent@^2.1.0, recursive-readdir-sync@^1.0.6, @vscode/vsce@^2.7.0, iconv-lite@^0.4.15, uuid@^7, string-hash@^1.1.3, node-rsa@^1.0.7, and urlencode@^1.1.0. Each of these packages is commonly used for XML parsing, URL encoding, analytics, string utilities, cryptographic helpers, and UUID generation; none of them are inherently malicious.
The findings list contains only low‑severity dependency entries and does not include any postinstall_* triggers, credential_* accesses, or network beacons that exfiltrate code. The secret findings bucket is empty, indicating that the extension does not attempt to read .env files, cloud credentials, or SSH keys. Moreover, no malware‑signature, malware, or obfuscation findings appear in the report, and the only category with entries is dependency, each marked low severity. This pattern matches the expected footprint of a typical npm‑based IDE extension that bundles a modest set of libraries to provide its functionality.
A potential objection is that the large number of dependency declarations (18 total when counting transitive packages not listed individually) could mask malicious code hidden inside one of the bundled libraries. However, every dependency cited is a widely distributed package with public documentation, and the extension’s public description explicitly references composer.json IntelliSense, which justifies the need to read and write project files. Additionally, the absence of any postinstall execution, credential access, or network‑exfiltration findings eliminates the possibility of hidden malicious payloads. Consequently, the objection does not change the assessment that the extension’s behavior aligns with legitimate development tooling.
In summary, the evidence demonstrates that the extension’s filesystem and process access is fully justified by its stated purpose of providing composer‑related IntelliSense and automation. No credential‑theft or data‑exfiltration activity is detected, and the sole findings are low‑severity dependency declarations that are typical for a functional IDE extension. Therefore, the extension should be classified as likely_false_positive.
Key Reasons
- No malicious indicator categories present
- All findings are low-severity dependency declarations
- Extension purpose matches observed file access
- No credential access or exfiltration findings
- High user count suggests vetted publication
False Positive Considerations
- high number of low-severity dependency entries
- absence of malicious categories
- no postinstall or credential findings
- findings correspond to normal npm dependencies
Reviewed 2026-05-23; recommended action: no action; model confidence 94%.
VS Code version history
Risk trend by version
27 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace