VS Code Marketplace Verified

Shopify Liquid

by Shopify · 366.6K users · 3.3 rating
e866dbdc-c7be-5770-bae4-839bac0f48bd | v3.11.10
44/ 100
MEDIUM risk
No change since v3.11.9
Analyst verdict
Review before use

The AI review rates the findings as likely false positive, but the risk score (44/100) still counts them.

No individual score drivers were recorded for this analysis.

Analysis record

Analysed
Yesterday
Version
v3.11.10
Artifact
SHA256 C49…03C
Source
Findings (non-IoC)

No Findings

All security checks passed

Publisher Evidence

Low

Shopify

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

97
Noisy-finding weight
x1.00
Publisher domain
shopify.com
Observed
Store verification signal
Verified publisher
Verified
Extension portfolio
12
Portfolio

11 evidence rows available.

No Threats Detected

This extension passed all security checks

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality strong.

The "Shopify Liquid" extension, published by Shopify, provides a developer experience for building Shopify themes. The extension has over 366,000 users on the Visual Studio Code marketplace. The security scan identified 32 findings, all classified as network observations. Every single finding points to the use of standard networking libraries within the bundled distribution files. Specifically, the scanner flagged NET-FETCH-extension/dist/browser/extension.js-15, NET-XMLHTTPREQUEST-extension/dist/browser/server.js-7297, and NET-SOCKET_IO-extension/dist/browser/extension.js-36782. These are indicators of standard web communication, not malicious data exfiltration. They are the scanner detecting the presence of the fetch API, XMLHttpRequest, and the socket.io library inside minified JavaScript bundles located in extension/dist/browser/ and extension/dist/node/.

A theme development tool inherently requires network access to communicate with the Shopify Admin API, download theme assets, and synchronize local changes with the remote store. The presence of socket.io strongly points to a live-reload or hot-module replacement feature, which relies on WebSockets to push updates to a local preview server when a developer saves a Liquid file. The extension declares no explicit host permissions or special capabilities in its manifest, and the scan found zero indicators of compromise, zero malware signatures, and zero secret-scanning hits. There is no evidence of credential theft, no attempts to read .env files or SSH keys, and no postinstall scripts executing arbitrary payloads.

The strongest counterargument to a clean bill of health is the sheer volume of network findings. Thirty-two medium-severity alerts might look alarming at a glance, prompting a reviewer to wonder if the extension is beaconing to an unknown command server. However, this volume is a direct artifact of how modern JavaScript is bundled. The dist/ directory contains compiled output from dozens of dependencies. Every time a bundled library uses fetch or XMLHttpRequest, the scanner logs a separate finding. The count reflects the size of the dependency tree. Furthermore, the extension is published directly by Shopify, a major public corporation with a massive reputation to protect, making the insertion of a supply chain backdoor highly improbable.

Ultimately, the filesystem and process access required by this extension are entirely justified by its stated purpose. Editing, previewing, and deploying Shopify themes requires reading local workspace files and spawning local development servers. The network calls are routed through standard, well-known APIs rather than obscure or suspicious domains. With no malicious signatures, no credential access, and no anomalous network endpoints, the findings represent the expected behavior of a legitimate, widely-used development tool.

Key Reasons

  • Published by verified developer Shopify with over 366,000 users
  • All 32 findings are standard network API calls (fetch, XMLHttpRequest, socket.io) in dist/ bundles
  • Zero malware signatures, zero IoCs, and zero credential access findings
  • Network access is fully justified for Shopify API communication and live preview features
  • No suspicious or anomalous network endpoints detected

False Positive Considerations

  • Bundled dependencies in dist/ files triggering multiplicative network findings
  • Standard web APIs like fetch and XMLHttpRequest flagged as network observations
  • socket.io library usage for live preview features misidentified as suspicious

Reviewed 2026-10-01; recommended action: suppress false positive; model confidence 95%.

VS Code version history

Risk trend by version

9 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
44
Change since first
-7
Change from previous
No change
Versions:
First analyzed version
3.10.0
Jan 19, 2026
Risk range
44 to 50
Across analyzed versions
Latest analyzed version
3.11.10
Sep 30, 2026
Selected version
medium
Version
v3.11.10
Yesterday
Risk score
44
Findings
32
Change vs previous
No change

Pick any point on the chart to explore that version's code below.

About This Extension

A complete developer experience for Shopify themes

Frequently Asked Questions