Score-based assessment (low risk, 28/100). Last analyst review covers version 1.70.18851.
Analysis record
- Analysed
- 5 days ago
- Version
- v1.74.19317
- Artifact
- SHA256 396…1E6
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
YARA Rule Matches
16 rules| Severity | Rule | Hits | Files | Metadata |
|---|---|---|---|---|
| LOW | credential env files | 4 | CHANGELOG.zh.mdCHANGELOG.ja.mdpackage.json +1 more | - |
| LOW | postinstall persistence mechanism | 4 | CHANGELOG.zh.mdCHANGELOG.ja.mdsyntaxes/phpx.json +1 more | - |
| LOW | DebuggerStatementsShouldNotBeUsed | 7 | CHANGELOG.zh.mdCHANGELOG.ja.mdpackage.json +4 more | - |
| LOW | UsingCommandLineArguments | 1 | out/src/extension.js | - |
| LOW | postinstall file download | 14 | LICENSE.mdreadme.mdpackage.nls.en.json +11 more | - |
| LOW | SQLInjection | 2 | webviews/toolkit.min.jsout/src/extension.js | - |
| LOW | NoUseWeakRandom | 2 | webviews/toolkit.min.jsout/src/extension.js | - |
| LOW | postinstall crypto operations | 3 | syntaxes/phpx.jsonout/src/extension.jswebviews/toolkit.min.js | - |
| LOW | UsingShellInterpreterWhenExecutingOSCommands | 1 | out/src/extension.js | - |
| LOW | postinstall file manipulation | 13 | LICENSE.mdpackage.jsonout/src/extension.js +10 more | - |
| LOW | postinstall system command | 17 | out/src/extension.jsLICENSE.mdextension.vsixmanifest +14 more | - |
| LOW | PM Email Sent By PHP Script | 1 | out/src/extension.js | - |
| LOW | postinstall environment access | 1 | webviews/toolkit.min.js | - |
| LOW | postinstall registry modification | 2 | syntaxes/phpx.jsonout/src/extension.js | - |
| LOW | postinstall obfuscation | 8 | LICENSE.mdpackage.nls.zh-cn.jsonpackage.nls.ja.json +5 more | - |
| LOW | postinstall network communication | 14 | package.nls.zh-cn.jsonpackage.nls.en.jsonout/src/extension.js +11 more | - |
Publisher Evidence
Lowdevsense
Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
12 evidence rows available.
Finding Categories
YARA Rules Matched
16 rules(94 hits)AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality strong.
The "PHP" extension by devsense (28.3M users) provides core development features including IntelliSense, debugging, and code formatting. Analysis found zero malicious indicators across all categories: no postinstall payload execution, no credential theft patterns, and no exfiltration mechanisms. Filesystem access is justified by the extension's purpose—reading PHP files for IntelliSense and linting is inherent to its functionality. Process spawning for debugging and local server management aligns with documented features. No findings reference sensitive files (.env, SSH keys, cloud credentials) or unauthorized network calls. The absence of obfuscation, malware signatures, or suspicious IoCs further confirms legitimacy. Strongest counterargument: high-permission extensions inherently pose risk. However, this extension's permissions are narrowly scoped to development tasks, and its publisher (devsense) maintains a long-standing reputation in the PHP ecosystem. No evidence suggests capability beyond stated purpose.
Key Reasons
- Zero malicious indicators detected across all analysis categories
- Filesystem/process access strictly aligned with PHP development requirements
- No credential access patterns targeting secrets or sensitive files
- High user adoption and verified publisher reputation
Reviewed 2026-05-23; recommended action: no action; model confidence 95%.
Open VSX version history
Risk trend by version
12 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace