VS Code Marketplace Verified

Meta VR

by Meta · 1.8K users · 5.0 rating
e2616446-733a-5ad9-90ed-a74356029de8 | v1.3.2
38/ 100
LOW risk
+36 since v1.3.2
74 → 38 · false positives removed
Risk verdict
No high-risk signal observed

Score-based assessment (low risk, 38/100). Last analyst review covers version 1.0.2.

Analysis record

Analysed
3 months ago
Version
v1.3.2
Artifact
SHA256 E1B…F16
Source
Findings (non-IoC)

Network indicator detail is shown below

1,608 aggregate findings were counted. 1,608 network indicators contributed to the aggregate finding count.

Network Indicators

Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.

1,608 total
...

Network indicators are queued for lazy loading

Scroll this section into view to load the detailed rows.

Publisher Evidence

Low

Meta

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

77
Noisy-finding weight
x1.00
Publisher domain
meta.com
Observed
Store verification signal
Verified publisher
Verified
Extension portfolio
6
Portfolio

12 evidence rows available.

Finding Categories

1,608
IoC Indicators

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality strong.

This extension is developed and published by Meta to support Horizon OS and Quest development. Based on the description, it functions as a bridge between the local IDE and Meta's development infrastructure, bundling tools like hzdb and an MCP (Model Context Protocol) server.

The capabilities required by this extension—reading workspace files, executing child processes, and external network communication—are standard for this category of development tool. An SDK extension must spawn language servers or build tools (process execution), read source code to provide features (file access), and communicate with vendor APIs (network calls). There are no findings in the evidence bundle suggesting credential theft, unauthorized exfiltration, or supply chain typosquatting. The extension is from a verified publisher (meta) and serves a clear, legitimate purpose for VR/AR developers. While powerful, this tool is benign in the context of professional software development.

Key Reasons

  • Verified official publisher (Meta)
  • Clear, functional purpose (SDK/DevTools)
  • Expected capabilities for an IDE SDK extension

False Positive Considerations

  • Benign use of child_process for language servers/build tools
  • Benign network calls to official vendor update/API endpoints
  • Workspace file access is a core feature, not suspicious behavior

Reviewed 2026-04-17; recommended action: no action; model confidence 95%.

VS Code version history

Risk trend by version

5 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
74
Change since first
+28
Change from previous
+36
Versions:
First analyzed version
1.0.1
Mar 11, 2026
Risk range
38 to 74
Across analyzed versions
Latest analyzed version
1.8.0
Sep 25, 2026
Selected version
high
Version
v1.8.0
6 days ago
Risk score
74
Findings
2285
Change vs previous
+36

Pick any point on the chart to explore that version's code below.

About This Extension

VS Code and Cursor extension for Meta Horizon OS and Meta Quest development, bundling the metavr CLI, MCP server registration, and Meta Quest developer skills.

Frequently Asked Questions