VS Code Marketplace Verified

Composer

by DEVSENSE · 6.7M users · 4.6 rating
990f59e9-8811-5e51-b7d9-4e1b66c4627d | v1.74.19317
31/ 100
LOW risk
No change since v1.74.19294
Analyst verdict
No high-risk signal observed

Based on the RiskyPlugins AI security review of the observed evidence.

Analysis record

Analysed
6 days ago
Version
v1.74.19317
Artifact
SHA256 2F4…907
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

17 detail rows

Publisher Evidence

Low

DEVSENSE

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

93
Noisy-finding weight
x1.00
Publisher domain
devsense.com
Observed
Store verification signal
Verified publisher
Verified
Extension portfolio
5
Portfolio

12 evidence rows available.

Finding Categories

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality strong.

Composer is advertised as an All‑In‑One Composer integration that supplies quick actions, command registration, automatic installation assists, task management, code‑lens support, diagnostics, and composer.json IntelliSense. Because the extension operates inside the IDE, it must be able to read project files — especially composer.json — and may spawn Node processes to resolve npm packages. The investigation of the extension’s package.json at /tmp/extract-46a5fdc07371c6341ff4621b7ab809620466c018e027e1937f2b955c6d193b18-1534519640/extension/package.json shows that it declares eleven npm dependencies: xmldom@^0.6.0, file-url@^2.0.0, applicationinsights@^1.8.10, escape-string-regexp@^1.0.5, http-proxy-agent@^2.1.0, recursive-readdir-sync@^1.0.6, @vscode/vsce@^2.7.0, iconv-lite@^0.4.15, uuid@^7, string-hash@^1.1.3, node-rsa@^1.0.7, and urlencode@^1.1.0. Each of these packages is commonly used for XML parsing, URL encoding, analytics, string utilities, cryptographic helpers, and UUID generation; none of them are inherently malicious.

The findings list contains only low‑severity dependency entries and does not include any postinstall_* triggers, credential_* accesses, or network beacons that exfiltrate code. The secret findings bucket is empty, indicating that the extension does not attempt to read .env files, cloud credentials, or SSH keys. Moreover, no malware‑signature, malware, or obfuscation findings appear in the report, and the only category with entries is dependency, each marked low severity. This pattern matches the expected footprint of a typical npm‑based IDE extension that bundles a modest set of libraries to provide its functionality.

A potential objection is that the large number of dependency declarations (18 total when counting transitive packages not listed individually) could mask malicious code hidden inside one of the bundled libraries. However, every dependency cited is a widely distributed package with public documentation, and the extension’s public description explicitly references composer.json IntelliSense, which justifies the need to read and write project files. Additionally, the absence of any postinstall execution, credential access, or network‑exfiltration findings eliminates the possibility of hidden malicious payloads. Consequently, the objection does not change the assessment that the extension’s behavior aligns with legitimate development tooling.

In summary, the evidence demonstrates that the extension’s filesystem and process access is fully justified by its stated purpose of providing composer‑related IntelliSense and automation. No credential‑theft or data‑exfiltration activity is detected, and the sole findings are low‑severity dependency declarations that are typical for a functional IDE extension. Therefore, the extension should be classified as likely_false_positive.

Key Reasons

  • No malicious indicator categories present
  • All findings are low-severity dependency declarations
  • Extension purpose matches observed file access
  • No credential access or exfiltration findings
  • High user count suggests vetted publication

False Positive Considerations

  • high number of low-severity dependency entries
  • absence of malicious categories
  • no postinstall or credential findings
  • findings correspond to normal npm dependencies

Reviewed 2026-05-23; recommended action: no action; model confidence 94%.

VS Code version history

Risk trend by version

27 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
31
Change since first
-10
Change from previous
No change
Versions:
First analyzed version
1.65.18354
Jan 23, 2026
Risk range
31 to 49
Across analyzed versions
Latest analyzed version
1.74.19317
Sep 25, 2026
Selected version
low
Version
v1.74.19317
6 days ago
Risk score
31
Findings
17
Change vs previous
No change

Pick any point on the chart to explore that version's code below.

About This Extension

All-in-One composer integration, quick actions, commands, automatic installation, tasks, code lenses, diagnostics, and composer.json IntelliSense.

Frequently Asked Questions