IntelliPHP - AI Autocomplete for PHP
The AI review rates the findings as likely false positive, but the risk score (65/100) still counts them.
Analysis record
- Analysed
- 4 days ago
- Version
- v0.12.17700
- Artifact
- SHA256 90A…0B6
- Source
- Findings (non-IoC)
Is IntelliPHP - AI Autocomplete for PHP safe?
Intelli-PHP adds AI code completion and intelligence features to PHP development in VS Code. The extension declares no host permissions and makes no network calls outside of standard VS Code update channels. Its bundled code includes two Windows DLLs (blingfiretokdll.dll and onnxruntime.dll) used for tokenization and machine learning inference, standard components for an AI-assisted tool.
The scan found two critical obfuscation flags on those native binaries, which are compiled DLLs and not obfuscated code. It also flagged 509 IoC detections, but these are artifacts from the scanner misreading minified JavaScript. Examples include incomplete domains like actions.cc and api.cc, which are fragments of property chains from bundled libraries, and the nonsensical domain birthpopuptypesapplyimagebeinguppernoteseveryshowsmeansextramatchtrackknownearlybegansuperpapernorthlearngivennamedendedtermspartsgroupbrandusingwomanfalsereadyaudiotakeswhile.com, a sure sign of extraction error.
No malware signatures matched the extension. The code-smell findings are expected noise from a complex language server. The extension has 7.8 million users and comes from devsense, a PHP tooling vendor with a track record, making a hidden malicious payload unlikely.
No Findings
All security checks passed
Publisher Evidence
Lowdevsense
Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
12 evidence rows available.
No Threats Detected
This extension passed all security checks
AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality strong.
Intelli-PHP is a code intelligence extension for PHP development distributed on OpenVSX. The extension declares no special host permissions and no explicit network endpoints in its manifest, relying instead on standard VS Code APIs for language features.
The 580 findings are heavily skewed toward IoC detections (509 medium-severity items) and code-smell rules (51 low-severity findings). The two critical findings — OBFUSCATION-NATIVE_BINARY_ADDON on blingfiretokdll.dll and onnxruntime.dll — are bundled native binaries used for tokenization and machine learning inference, which are legitimate components for an AI-assisted PHP tool. These are not obfuscated code but compiled Windows DLLs, a standard mechanism for performance-critical operations in IDE extensions.
The IoC findings consist almost entirely of false positives from the XIOC extractor. The listed endpoints include incomplete domain fragments (2fwww.in, actions.cc, api.cc, arena.cc, base.cc) that are characteristic of misread minified JavaScript property chains (b.call, h.next, g.api) and generic programming-language identifiers (allocator.cc, builder.cc, bitstate.cc) extracted from bundled JavaScript libraries. The endpoint birthpopuptypesapplyimagebeinguppernoteseveryshowsmeansextramatchtrackknownearlybegansuperpapernorthlearngivennamedendedtermspartsgroupbrandusingwomanfalsereadyaudiotakeswhile.com is clearly an artifact of domain concatenation from minified code. The presence of legitimate ONNX schema URIs (ai.onnx.preview.training, ai.onnx.training) mixed with noise confirms the extraction is unreliable.
No malware signatures matched (0/580). The code-smell rules fired on patterns like environment variable access and process spawning that are normal for a language server extension. The 18 dependency findings reflect bundled npm packages, expected overhead for a complex tool.
The extension has 7.8 million users and is published by devsense, a known PHP tooling vendor. This user base and publisher track record make a malicious payload unlikely to remain undetected.
The strongest counterargument is that native DLLs in extensions can be weaponized for credential theft or command execution. However, the extension declares no host permissions to access the filesystem or run processes outside its sandboxed context, and no evidence in the bundle shows data exfiltration attempts or suspicious credential access patterns.
Key Reasons
- 509 IoC detections are artifacts from minified code extraction, not real network communication
- Native binaries (onnxruntime.dll, blingfiretokdll.dll) are legitimate components for ML-based tokenization
- Zero malware signatures matched across all findings
- Extension declares no host permissions or special capabilities
- Large user base (7.8M) and established publisher (devsense) make undetected malicious behavior implausible
False Positive Considerations
- XIOC extractor producing massive false positives from minified JavaScript property chains (b.call, h.api misread as domains)
- Bundled npm libraries triggering 18 dependency findings and hundreds of generic IoC matches
- Native DLL binaries flagged as obfuscation when they are compiled executables, not obfuscated code
Reviewed 2026-09-29; recommended action: suppress false positive; model confidence 85%.
Open VSX version history
Risk trend by version
2 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace