PHP Profiler
The AI review rates the findings as likely false positive, but the risk score (42/100) still counts them.
Analysis record
- Analysed
- 1 weeks ago
- Version
- v1.74.19317
- Artifact
- SHA256 9C0…C66
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
YARA Rule Matches
14 rules| Severity | Rule | Hits | Files | Metadata |
|---|---|---|---|---|
| LOW | postinstall file download | 6 | webviews/codicon.csswebviews/codicon.ttfout/src/extension.js +3 more | - |
| LOW | SQLInjection | 1 | webviews/toolkit.min.js | - |
| LOW | NoUseWeakRandom | 2 | out/src/extension.jswebviews/toolkit.min.js | - |
| LOW | DebuggerStatementsShouldNotBeUsed | 1 | package.json | - |
| LOW | UsingCommandLineArguments | 1 | out/src/extension.js | - |
| LOW | postinstall crypto operations | 3 | out/src/extension.jswebviews/toolkit.min.jspackage.json | - |
| LOW | postinstall file manipulation | 6 | webviews/codicon.csswebviews/codicon.ttfwebviews/main.js +3 more | - |
| LOW | postinstall system command | 6 | webviews/codicon.ttfwebviews/codicon.cssextension.vsixmanifest +3 more | - |
| LOW | postinstall environment access | 2 | webviews/main.jswebviews/toolkit.min.js | - |
| LOW | postinstall obfuscation | 6 | webviews/main.jsout/src/extension.jsLICENSE.md +3 more | - |
| LOW | postinstall network communication | 5 | webviews/codicon.csswebviews/codicon.ttfout/src/extension.js +2 more | - |
| LOW | UsingShellInterpreterWhenExecutingOSCommands | 1 | out/src/extension.js | - |
| LOW | credential env files | 1 | out/src/extension.js | - |
| LOW | postinstall persistence mechanism | 1 | out/src/extension.js | - |
Publisher Evidence
LowDEVSENSE
Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
12 evidence rows available.
Finding Categories
YARA Rules Matched
14 rules(42 hits)AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality strong.
The PHP Profiler extension declares a set of npm dependencies in /tmp/extract-afa2a1671dff3e69a8a2fc5c4ef1f45f602e757805cba134d48f081cdbb8fab3-1052347247/extension/package.json (e.g., uuid@^7, vscode-languageclient@^7.0.0, xmlhttprequest@^1.8.0). These entries are typical for a language‑client‑based tool that reads Xdebug profiling files and presents them to the user. No findings report the execution of shell commands, downloading external payloads, or invoking child_process.exec, so the process‑spawning capability expected for a language server is justified by the extension’s purpose of parsing and visualising profiling data.
There are no secret‑access findings such as reads of .env, .ssh, or cloud‑credential files; the only file interactions are the declared dependencies and the code that processes profiling output. Consequently, the extension does not attempt to harvest real credentials.
A potential counterargument could point to the large number of low‑severity dependency findings as a sign of excessive third‑party code that might hide malicious logic. However, all findings are limited to the dependency category, originate from the static package.json, and no code‑smell, IoC, or network‑related indicators were triggered. The presence of these dependencies is consistent with normal development‑tool behavior and does not constitute evidence of harmful intent.
Key Reasons
- Only dependency declarations found, no executable or network‑related code
- No credential‑related file reads detected
- Findings limited to low‑severity ‘dependency’ category
False Positive Considerations
- Bundled dependencies generate many harmless low‑severity entries
- Absence of IoC or malware signatures
Reviewed 2026-05-23; recommended action: no action; model confidence 92%.
VS Code version history
Risk trend by version
27 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace