VS Code Marketplace Verified

Draw.io Integration

by Henning Dieterichs · 4.2M users · 4.9 rating
cbfdfdd6-3b4d-55ca-b13e-04a4fe8b93ea | v1.11.260924036
82/ 100
HIGH risk
No change since v1.9.260911031
Analyst verdict
Review before use

The AI review rates the findings as likely false positive, but the risk score (82/100) still counts them.

Analysis record

Analysed
5 days ago
Version
v1.11.260924036
Artifact
SHA256 4EA…EDC
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

26 detail rows

YARA Rule Matches

1 rule
SeverityRuleHitsFilesMetadata
HIGHsupply chain sourcemap appended iife 4
drawio/src/main/webapp/js/app.min.jsdrawio/src/main/webapp/js/viewer-static.min.jsdrawio/src/main/webapp/js/integrate.min.js +1 more
-

Publisher Evidence

Low

Henning Dieterichs

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

100
Noisy-finding weight
x1.00
Publisher domain
hediet.de
Observed
Store verification signal
Verified publisher
Verified
Extension portfolio
14
Portfolio

11 evidence rows available.

Finding Categories

4
Malware Signatures
22
Network

YARA Rules Matched

1 rule(4 hits)
supply chain sourcemap appended iife

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality strong.

The Draw.io Integration extension by hediet is a legitimate VS Code extension with over 3.8 million users that embeds the Draw.io diagramming tool into the development environment. Analysis reveals 1,359 total findings, but 1,355 of these are code-smell detections from YARA rules matching basic JavaScript patterns, not actual malicious behavior.

The eight malware-signature findings appear in minified and asset files rather than executable code. The YARA--postinstall_registry_modification and YARA--postinstall_crypto_operations detections occur in /extension/drawio/src/main/webapp/js/stencils.min.js, a minified JavaScript file that bundles legitimate stencil library code. Multiple YARA--postinstall_network_communication matches in SVG image files like /extension/drawio/src/main/webapp/img/lib/azure2/storage/Storage_Accounts_Classic.svg are false positives—SVG files contain XML markup that can trigger network-related YARA patterns but cannot execute code. The YARA--postinstall_file_manipulation finding in /extension/drawio/src/main/webapp/math/es5/input/mml/entities.js matches mathematical entity definitions, not file manipulation logic.

Four network findings are expected for this extension's functionality. The NET-XMLHTTPREQUEST detections in embed.dev.js and mxODPicker.js files support embedding and OneDrive integration features. The NET-WEBSOCKET call in app.min.js enables real-time collaboration, which is core to Draw.io's purpose.

No credential-access findings target sensitive files like .env, .ssh, or cloud credentials. Zero secret detections were recorded, confirming no credential theft indicators exist in the codebase.

The strongest counterargument is the 1,355 high-severity code-smell findings. However, these are known false positives from YARA rules designed to catch basic JavaScript patterns—fetch, exec, fs, crypto operations—that are normal for any non-trivial extension. The postinstall_* YARA rules match legitimate Node.js patterns, not malicious post-install payloads. This extension's network calls and file access are justified by its stated purpose of integrating a diagramming tool into VS Code.

Given the extension's popularity, verified developer status, and the nature of all findings being in minified/bundled code or known false-positive patterns, this is a clear false positive that should be suppressed.

Key Reasons

  • 1,355 of 1,359 findings are code-smell YARA noise
  • Malware-signature findings are in minified/bundled files and SVG images
  • No credential-access or secret findings detected
  • 3.8M+ users and verified developer indicate legitimacy
  • Network calls justified by OneDrive and collaboration features

False Positive Considerations

  • Code-smell YARA rules matching basic JavaScript patterns
  • Minified/bundled JavaScript triggering false positives
  • SVG image files incorrectly flagged by YARA rules
  • Postinstall_* rules matching legitimate Node.js patterns

Reviewed 2026-05-23; recommended action: suppress false positive; model confidence 90%.

VS Code version history

Risk trend by version

7 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
82
Change since first
+32
Change from previous
No change
Versions:
First analyzed version
1.9.250226013
Apr 5, 2026
Risk range
44 to 82
Across analyzed versions
Latest analyzed version
1.11.260924036
Sep 26, 2026
Selected version
high
Version
v1.11.260924036
5 days ago
Risk score
82
Findings
26
Change vs previous
No change

Pick any point on the chart to explore that version's code below.

About This Extension

This unofficial extension integrates Draw.io into VS Code.

Frequently Asked Questions