VS Code Marketplace Verified

Ruby LSP

by Shopify · 1.9M users · 2.8 rating
bc27965b-1a71-59fe-8915-e929ea3fd82c | v0.10.6
31/ 100
LOW risk
No change since v0.10.4
Analyst verdict
Benign but powerful

From the RiskyPlugins AI security review of the observed evidence.

No individual score drivers were recorded for this analysis.

Analysis record

Analysed
2 weeks ago
Version
v0.10.6
Artifact
SHA256 E72…FF2
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

2 detail rows

Publisher Evidence

Low

Shopify

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

100
Noisy-finding weight
x1.00
Publisher domain
shopify.com
Observed
Store verification signal
Verified publisher
Verified
Extension portfolio
12
Portfolio

11 evidence rows available.

Finding Categories

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality strong.

The Ruby LSP extension for VS Code, developed by Shopify, has been analyzed for potential security risks. The extension's purpose is to connect with the Ruby Language Server, and its dependencies include vscode-languageclient and vscode-jsonrpc. The findings indicate that the extension has a dependency on these two libraries, which is justified by its stated purpose. There are no findings related to credential-access or malware signatures. The strongest counterargument to the verdict could be that the extension has a large user base and is developed by a reputable company, which may suggest a lower risk. However, this does not change the conclusion that the extension's dependencies and access are justified by its purpose. The DEP-vscode-languageclient-^9.0.1 and DEP-vscode-jsonrpc-^8.2.1 findings in the package.json file at /tmp/extract-3f32b77106202e64b26b860f68e4c16b73f5b4e6f888ef8e7f826c75b645c319-1741394318/extension/ support this conclusion.

Key Reasons

  • Justified dependencies
  • No credential-access or malware findings
  • Reputable developer

Reviewed 2026-05-23; recommended action: no action; model confidence 90%.

VS Code version history

Risk trend by version

7 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
31
Change since first
-10
Change from previous
No change
Versions:
First analyzed version
0.9.33
Jan 23, 2026
Risk range
31 to 42
Across analyzed versions
Latest analyzed version
0.10.6
Aug 1, 2026
Selected version
low
Version
v0.10.6
2 months ago
Risk score
31
Findings
2
Change vs previous
No change

Pick any point on the chart to explore that version's code below.

About This Extension

VS Code plugin for connecting with the Ruby LSP

Frequently Asked Questions