VS Code Marketplace Verified

PHP Profiler

by DEVSENSE · 6.6M users · 5.0 rating
d6d32009-a3a9-5fc8-b647-732ed4aaccca | v1.74.19317
42/ 100
MEDIUM risk
-7 since v1.74.19252
Analyst verdict
Review before use

The AI review rates the findings as likely false positive, but the risk score (42/100) still counts them.

Analysis record

Analysed
1 weeks ago
Version
v1.74.19317
Artifact
SHA256 9C0…C66
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

65 detail rows

YARA Rule Matches

14 rules
SeverityRuleHitsFilesMetadata
LOWpostinstall file download 6
webviews/codicon.csswebviews/codicon.ttfout/src/extension.js +3 more
-
LOWSQLInjection 1
webviews/toolkit.min.js
-
LOWNoUseWeakRandom 2
out/src/extension.jswebviews/toolkit.min.js
-
LOWDebuggerStatementsShouldNotBeUsed 1
package.json
-
LOWUsingCommandLineArguments 1
out/src/extension.js
-
LOWpostinstall crypto operations 3
out/src/extension.jswebviews/toolkit.min.jspackage.json
-
LOWpostinstall file manipulation 6
webviews/codicon.csswebviews/codicon.ttfwebviews/main.js +3 more
-
LOWpostinstall system command 6
webviews/codicon.ttfwebviews/codicon.cssextension.vsixmanifest +3 more
-
LOWpostinstall environment access 2
webviews/main.jswebviews/toolkit.min.js
-
LOWpostinstall obfuscation 6
webviews/main.jsout/src/extension.jsLICENSE.md +3 more
-
LOWpostinstall network communication 5
webviews/codicon.csswebviews/codicon.ttfout/src/extension.js +2 more
-
LOWUsingShellInterpreterWhenExecutingOSCommands 1
out/src/extension.js
-
LOWcredential env files 1
out/src/extension.js
-
LOWpostinstall persistence mechanism 1
out/src/extension.js
-

Publisher Evidence

Low

DEVSENSE

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

93
Noisy-finding weight
x1.00
Publisher domain
devsense.com
Observed
Store verification signal
Verified publisher
Verified
Extension portfolio
5
Portfolio

12 evidence rows available.

Finding Categories

YARA Rules Matched

14 rules(42 hits)
postinstall file download SQLInjection NoUseWeakRandom DebuggerStatementsShouldNotBeUsed UsingCommandLineArguments postinstall crypto operations postinstall file manipulation postinstall system command postinstall environment access postinstall obfuscation postinstall network communication UsingShellInterpreterWhenExecutingOSCommands credential env files postinstall persistence mechanism

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality strong.

The PHP Profiler extension declares a set of npm dependencies in /tmp/extract-afa2a1671dff3e69a8a2fc5c4ef1f45f602e757805cba134d48f081cdbb8fab3-1052347247/extension/package.json (e.g., uuid@^7, vscode-languageclient@^7.0.0, xmlhttprequest@^1.8.0). These entries are typical for a language‑client‑based tool that reads Xdebug profiling files and presents them to the user. No findings report the execution of shell commands, downloading external payloads, or invoking child_process.exec, so the process‑spawning capability expected for a language server is justified by the extension’s purpose of parsing and visualising profiling data.

There are no secret‑access findings such as reads of .env, .ssh, or cloud‑credential files; the only file interactions are the declared dependencies and the code that processes profiling output. Consequently, the extension does not attempt to harvest real credentials.

A potential counterargument could point to the large number of low‑severity dependency findings as a sign of excessive third‑party code that might hide malicious logic. However, all findings are limited to the dependency category, originate from the static package.json, and no code‑smell, IoC, or network‑related indicators were triggered. The presence of these dependencies is consistent with normal development‑tool behavior and does not constitute evidence of harmful intent.

Key Reasons

  • Only dependency declarations found, no executable or network‑related code
  • No credential‑related file reads detected
  • Findings limited to low‑severity ‘dependency’ category

False Positive Considerations

  • Bundled dependencies generate many harmless low‑severity entries
  • Absence of IoC or malware signatures

Reviewed 2026-05-23; recommended action: no action; model confidence 92%.

VS Code version history

Risk trend by version

27 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
42
Change since first
No change
Change from previous
-7
Versions:
First analyzed version
1.65.18354
Jan 23, 2026
Risk range
31 to 49
Across analyzed versions
Latest analyzed version
1.74.19317
Sep 19, 2026
Selected version
medium
Version
v1.74.19317
1 weeks ago
Risk score
42
Findings
65
Change vs previous
-7

Pick any point on the chart to explore that version's code below.

About This Extension

Support for PHP (Xdebug) profiling files and inspecting them.

Frequently Asked Questions