OpenVSX Registry Verified

PHP

9e92090d-87fb-56a9-a73d-3baed987cc5c | v1.74.19317
28/ 100
LOW risk
-18 since v1.58.17223
46 → 28 · false positives removed
Risk verdict
No high-risk signal observed

Score-based assessment (low risk, 28/100). Last analyst review covers version 1.70.18851.

Analysis record

Analysed
5 days ago
Version
v1.74.19317
Artifact
SHA256 396…1E6
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

94 detail rows

YARA Rule Matches

16 rules
SeverityRuleHitsFilesMetadata
LOWcredential env files 4
CHANGELOG.zh.mdCHANGELOG.ja.mdpackage.json +1 more
-
LOWpostinstall persistence mechanism 4
CHANGELOG.zh.mdCHANGELOG.ja.mdsyntaxes/phpx.json +1 more
-
LOWDebuggerStatementsShouldNotBeUsed 7
CHANGELOG.zh.mdCHANGELOG.ja.mdpackage.json +4 more
-
LOWUsingCommandLineArguments 1
out/src/extension.js
-
LOWpostinstall file download 14
LICENSE.mdreadme.mdpackage.nls.en.json +11 more
-
LOWSQLInjection 2
webviews/toolkit.min.jsout/src/extension.js
-
LOWNoUseWeakRandom 2
webviews/toolkit.min.jsout/src/extension.js
-
LOWpostinstall crypto operations 3
syntaxes/phpx.jsonout/src/extension.jswebviews/toolkit.min.js
-
LOWUsingShellInterpreterWhenExecutingOSCommands 1
out/src/extension.js
-
LOWpostinstall file manipulation 13
LICENSE.mdpackage.jsonout/src/extension.js +10 more
-
LOWpostinstall system command 17
out/src/extension.jsLICENSE.mdextension.vsixmanifest +14 more
-
LOWPM Email Sent By PHP Script 1
out/src/extension.js
-
LOWpostinstall environment access 1
webviews/toolkit.min.js
-
LOWpostinstall registry modification 2
syntaxes/phpx.jsonout/src/extension.js
-
LOWpostinstall obfuscation 8
LICENSE.mdpackage.nls.zh-cn.jsonpackage.nls.ja.json +5 more
-
LOWpostinstall network communication 14
package.nls.zh-cn.jsonpackage.nls.en.jsonout/src/extension.js +11 more
-

Publisher Evidence

Low

devsense

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

55
Noisy-finding weight
x1.00
Publisher domain
No domain
Missing
Store verification signal
Verified publisher
Verified
Extension portfolio
4
Portfolio

12 evidence rows available.

Finding Categories

YARA Rules Matched

16 rules(94 hits)
credential env files postinstall persistence mechanism DebuggerStatementsShouldNotBeUsed UsingCommandLineArguments postinstall file download SQLInjection NoUseWeakRandom postinstall crypto operations UsingShellInterpreterWhenExecutingOSCommands postinstall file manipulation postinstall system command PM Email Sent By PHP Script postinstall environment access postinstall registry modification postinstall obfuscation postinstall network communication

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality strong.

The "PHP" extension by devsense (28.3M users) provides core development features including IntelliSense, debugging, and code formatting. Analysis found zero malicious indicators across all categories: no postinstall payload execution, no credential theft patterns, and no exfiltration mechanisms. Filesystem access is justified by the extension's purpose—reading PHP files for IntelliSense and linting is inherent to its functionality. Process spawning for debugging and local server management aligns with documented features. No findings reference sensitive files (.env, SSH keys, cloud credentials) or unauthorized network calls. The absence of obfuscation, malware signatures, or suspicious IoCs further confirms legitimacy. Strongest counterargument: high-permission extensions inherently pose risk. However, this extension's permissions are narrowly scoped to development tasks, and its publisher (devsense) maintains a long-standing reputation in the PHP ecosystem. No evidence suggests capability beyond stated purpose.

Key Reasons

  • Zero malicious indicators detected across all analysis categories
  • Filesystem/process access strictly aligned with PHP development requirements
  • No credential access patterns targeting secrets or sensitive files
  • High user adoption and verified publisher reputation

Reviewed 2026-05-23; recommended action: no action; model confidence 95%.

Open VSX version history

Risk trend by version

12 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
42
Change since first
+14
Change from previous
-18
Versions:
First analyzed version
1.67.18583
Mar 10, 2026
Risk range
28 to 72
Across analyzed versions
Latest analyzed version
1.40.14137
Sep 19, 2026
Selected version
medium
Version
v1.40.14137
1 weeks ago
Risk score
42
Findings
99
Change vs previous
-18

Pick any point on the chart to explore that version's code below.

About This Extension

All-in-One PHP support - IntelliSense, Debug, Formatter, Code Lenses, Code Fixes, Linting, Refactoring, PHPUnit Tests, Web Server, and more.

Frequently Asked Questions