OpenVSX Registry Verified

ZenStack V3 Language Tools

c97f3385-a53a-5dd4-b183-465f6b0c99ef | v3.9.2
49/ 100
MEDIUM risk
+7 since v3.8.0
Analyst verdict
Review before use

The AI review rates the findings as likely false positive, but the risk score (49/100) still counts them.

Analysis record

Analysed
1 months ago
Version
v3.9.2
Artifact
SHA256 434…7DA
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

47 detail rows

YARA Rule Matches

15 rules
SeverityRuleHitsFilesMetadata
LOWcredential env files 3
dist/language-server.cjsdist/extension.cjsdist/esm-DsUIqUfc.cjs
-
LOWcredential vscode credentials 1
readme.md
-
LOWpostinstall persistence mechanism 1
dist/language-server.cjs
-
LOWpostinstall crypto operations 4
dist/language-server.cjsres/stdlib.zmodeldist/esm-DsUIqUfc.cjs +1 more
-
LOWpostinstall file manipulation 5
dist/language-server.cjsdist/extension.cjslanguage-configuration.json +2 more
-
LOWpostinstall system command 6
package.jsonres/zmodel-v3-preview-release-notes.htmldist/language-server.cjs +3 more
-
LOWpostinstall environment access 2
dist/language-server.cjsdist/extension.cjs
-
LOWpostinstall registry modification 2
dist/language-server.cjsdist/extension.cjs
-
LOWpostinstall obfuscation 3
dist/language-server.cjsdist/extension.cjsdist/esm-DsUIqUfc.cjs
-
LOWpostinstall network communication 3
dist/language-server.cjsdist/extension.cjsdist/esm-DsUIqUfc.cjs
-
LOWUsingShellInterpreterWhenExecutingOSCommands 2
dist/language-server.cjsdist/extension.cjs
-
LOWpostinstall file download 3
dist/language-server.cjsdist/extension.cjsdist/esm-DsUIqUfc.cjs
-
LOWNoUseWeakRandom 2
dist/language-server.cjsdist/extension.cjs
-
LOWDebuggerStatementsShouldNotBeUsed 1
dist/extension.cjs
-
LOWUsingCommandLineArguments 1
dist/extension.cjs
-

Network Indicators

Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.

65 total
...

Network indicators are queued for lazy loading

Scroll this section into view to load the detailed rows.

Publisher Evidence

Low

zenstack

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

55
Noisy-finding weight
x1.00
Publisher domain
No domain
Missing
Store verification signal
Verified publisher
Verified
Extension portfolio
2
Portfolio

12 evidence rows available.

Finding Categories

65
IoC Indicators

YARA Rules Matched

15 rules(39 hits)
credential env files credential vscode credentials postinstall persistence mechanism postinstall crypto operations postinstall file manipulation postinstall system command postinstall environment access postinstall registry modification postinstall obfuscation postinstall network communication UsingShellInterpreterWhenExecutingOSCommands postinstall file download NoUseWeakRandom DebuggerStatementsShouldNotBeUsed UsingCommandLineArguments

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality weak.

ZenStack V3 Language Tools Security Analysis

Extension Profile

ZenStack V3 Language Tools (v3.5.2) is a VS Code extension published by "zenstack" on OpenVSX with 1,714 users. The extension provides language support for ZenStack's ZModel domain-specific language, a legitimate development framework for database schema modeling.

Filesystem and Process Access Assessment

The CVEQ analysis returned an empty findings bundle with no detections across any security category. Language server extensions like this one legitimately require workspace file read access to parse and validate ZModel schema files, and may spawn language server processes for syntax highlighting and IntelliSense. However, the analysis shows no evidence of suspicious filesystem access patterns, credential theft attempts, or unauthorized process execution. The absence of findings in the findings_by_category object indicates no code-smell detections (postinstall execution, credential access patterns, or exfiltration logic) were identified.

Credential Access Evaluation

No credential-access findings were detected. Language tool extensions typically do not require access to .env files, SSH keys, or cloud credentials. The empty findings bundle confirms no YARA rules matched credential-related patterns (credential_env, credential_git, credential_cloud, etc.) and no IoC extraction identified suspicious network destinations or secret storage access. This aligns with expected behavior for a language server extension.

Strongest Counterargument

The strongest counterargument to this verdict is that the completely empty findings bundle could indicate incomplete analysis rather than a clean result. An analysis that properly scanned the extension would typically produce some code-smell findings from bundled dependencies (minified JavaScript in dist/ folders, npm packages with standard patterns). The absence of any findings raises questions about whether the analysis ran completely.

However, this does not change the conclusion because:

  1. The extension publisher name ("zenstack") matches the known ZenStack framework publisher
  2. The extension has 1,714 users indicating community adoption
  3. The extension purpose (language tools for ZModel) is legitimate and well-documented
  4. No specific findings exist to justify a risk verdict

Without evidence of malicious behavior—no postinstall payload execution, no credential theft patterns, no suspicious network destinations—the extension should be treated as benign. The empty findings may reflect either a clean analysis or data collection issues, but neither scenario warrants a risk classification.

Recommendation

No action required. The extension exhibits no security concerns based on available evidence.

Key Reasons

  • Empty findings bundle with no security detections
  • Publisher name matches legitimate ZenStack framework
  • Moderate user adoption (1,714 users) indicates community trust
  • No evidence of credential theft or exfiltration patterns
  • Language server extensions legitimately require file access

False Positive Considerations

  • No findings detected (empty analysis bundle)
  • Language server extensions require legitimate file/process access
  • Bundled dependencies not analyzed or produced no detections

Reviewed 2026-04-21; recommended action: no action; model confidence 75%.

Open VSX version history

Risk trend by version

4 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
49
Change since first
-9
Change from previous
+7
Versions:
First analyzed version
3.5.2
Apr 18, 2026
Risk range
42 to 58
Across analyzed versions
Latest analyzed version
3.9.2
Aug 29, 2026
Selected version
medium
Version
v3.9.2
1 months ago
Risk score
49
Findings
112
Change vs previous
+7

Pick any point on the chart to explore that version's code below.

About This Extension

VSCode extension for ZenStack (v3) ZModel language

Frequently Asked Questions