OpenVSX Registry Verified

KIDE C#

by kide
a3585538-e148-58d4-b63d-bac124fb759b | v26.9.163
65/ 100
MEDIUM risk
Risk verdict
Review before use

Score-based assessment (medium risk, 65/100). No analyst review available.

Analysis record

Analysed
1 weeks ago
Version
v26.9.163
Artifact
SHA256 DBB…1F6
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

1000 detail rows
Showing 25 of 640 · highest severity first

YARA Rule Matches

11 rules
SeverityRuleHitsFilesMetadata
LOWpostinstall file download 74
.roslyn/Microsoft.CodeAnalysis.LanguageServer.xmlpackage.jsonpackage.nls.pt-br.json +71 more
-
LOWNoUseWeakRandom 1
dist/extension.js
-
LOWDebuggerStatementsShouldNotBeUsed 54
l10n/bundle.l10n.pt-br.json.roslyn/Microsoft.CodeAnalysis.Remote.Workspaces.xml.roslyn/Microsoft.CodeAnalysis.CSharp.dll +51 more
-
LOWUsingCommandLineArguments 1
dist/extension.js
-
LOWpostinstall system command 99
l10n/bundle.l10n.ko.json.opencode/package-lock.json.roslyn/Microsoft.CodeAnalysis.Workspaces.xml +96 more
-
LOWpostinstall registry modification 3
.roslyn/Microsoft.CodeAnalysis.CSharp.Features.pdb.roslyn/Microsoft.CodeAnalysis.Workspaces.MSBuild.xml.roslyn/Microsoft.CodeAnalysis.LanguageServer.ExternalAccess.pdb
-
LOWpostinstall crypto operations 46
.roslyn/Microsoft.CodeAnalysis.pdbsnippets/csharp.json.roslyn/Microsoft.CodeAnalysis.LanguageServer.deps.json +43 more
-
LOWUsingShellInterpreterWhenExecutingOSCommands 1
dist/extension.js
-
LOWOriginsNotVerified 1
dist/extension.js
-
LOWpostinstall file manipulation 40
.roslyn/Microsoft.CodeAnalysis.Remote.Razor.xml.roslyn/Targets/Microsoft.NET.Sdk.Razor.DesignTime.targetsthemes/vs2019_light.json +37 more
-
LOWpostinstall network communication 40
.roslyn/Microsoft.CodeAnalysis.CSharp.Workspaces.pdb.roslyn/Microsoft.CodeAnalysis.Workspaces.xml.roslyn/Microsoft.CodeAnalysis.ExternalAccess.CompilerDeveloperSDK.pdb +37 more
-

Network Indicators

Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.

2,166 total
...

Network indicators are queued for lazy loading

Scroll this section into view to load the detailed rows.

Publisher Evidence

Low

kide

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

55
Noisy-finding weight
x1.00
Publisher domain
No domain
Missing
Store verification signal
Verified publisher
Verified
Extension portfolio
2
Portfolio

12 evidence rows available.

Finding Categories

632
Obfuscation
8
Network
2,166
IoC Indicators

YARA Rules Matched

11 rules(360 hits)
postinstall file download NoUseWeakRandom DebuggerStatementsShouldNotBeUsed UsingCommandLineArguments postinstall system command postinstall registry modification postinstall crypto operations UsingShellInterpreterWhenExecutingOSCommands OriginsNotVerified postinstall file manipulation postinstall network communication

Security Analysis Summary

Security Analysis Overview

KIDE C# is a OpenVSX Registry extension published by kide. Version 26.9.163 has been analyzed by the Risky Plugins security platform, receiving a risk score of 64.99/100 (MEDIUM risk) based on 3328 security findings.

Risk Assessment

This extension presents moderate security risk. Several findings were detected that may warrant attention. Users should carefully review the permissions and findings before installation.

Findings Breakdown

  • Critical: 632 finding(s)
  • Medium: 2174 finding(s)
  • Low: 522 finding(s)

What Was Analyzed

The security assessment covers multiple analysis categories:

  • Malware Detection: YARA rule matching against 2,400+ malware signatures
  • Secret Detection: Scanning for exposed API keys, tokens, and credentials
  • Static Analysis: Code-level security analysis for common vulnerability patterns
  • Network Analysis: Detection of suspicious network communications and endpoints
  • Obfuscation Detection: Identification of code obfuscation techniques

Developer Information

KIDE C# is published by kide on the OpenVSX Registry marketplace.

Recommendation

This extension is not recommended for installation without thorough manual review. Consider alternatives with lower risk scores, or contact the developer to address the identified security concerns.

About This Extension

Base language support for C#

Frequently Asked Questions