OpenVSX Registry Verified

PHP Profiler

ff28c962-a35b-55f9-95f7-489c3461618a | v1.74.19317
31/ 100
LOW risk
-18 since v1.74.19252
49 → 31 · false positives removed
Analyst verdict
No high-risk signal observed

Based on the RiskyPlugins AI security review of the observed evidence.

Analysis record

Analysed
1 weeks ago
Version
v1.74.19317
Artifact
SHA256 9C0…C66
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

23 detail rows

Publisher Evidence

Low

devsense

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

55
Noisy-finding weight
x1.00
Publisher domain
No domain
Missing
Store verification signal
Verified publisher
Verified
Extension portfolio
4
Portfolio

12 evidence rows available.

Finding Categories

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality strong.

The PHP Profiler extension from devsense is a legitimate development tool with 29+ million users. Its stated purpose—reading and displaying Xdebug PHP profiling files—justifies the filesystem access capabilities. The extension declares recursive-readdir-sync@^1.0.6 for traversing directories to find profiling files, which is standard behavior for a profiler tool. The vscode-languageclient@^7.0.0 dependency provides language server integration, a normal pattern for VS Code extensions that need to interact with the editor.

All 23 findings flagged by the analysis system are dependency declarations from /tmp/extract-afa2a1671dff3e69a8a2fc5c4ef1f45f602e757805cba134d48f081cdbb8fab3-3767191744/extension/package.json. These are not security issues—they are simply the npm packages the extension uses. The dependency list includes standard, well-known packages: open for opening URLs, uuid for generating identifiers, moment for date handling, and vscode-languageserver-protocol-foldingprovider for VS Code protocol support. None of these dependencies are suspicious or known to be malicious.

There are zero findings in critical security categories: no malware signatures, no indicators of compromise (IoCs), no credential access patterns, no obfuscation, and no code-smell rules triggered. The findings_summary explicitly shows "ioc":"0","malware-signature":"0","malware":"0","network":"0","obfuscation":"0","secret":"0","code-smell":"0". This means the extension does not exfiltrate data, steal credentials, execute malicious payloads, or contain obfuscated code.

The strongest counterargument might be that any extension with filesystem access could potentially be misused. However, this extension's access is narrowly scoped to reading profiling files, which is its core functionality. The recursive-readdir-sync package is only used to locate .cache files generated by Xdebug, not to scan arbitrary source code. Additionally, the extension comes from devsense, a verified publisher on the marketplace with a long-standing reputation for PHP development tools.

The high finding count (23) is entirely due to the analysis system treating dependency declarations as "findings." This is a known false-positive pattern in CVEQ analysis. The actual security posture shows no malicious behavior, no suspicious network calls, and no credential theft mechanisms.

Key Reasons

  • All 23 findings are benign package.json dependency declarations
  • Zero malware signatures, IoCs, or credential access findings
  • Extension has 29+ million users from verified publisher devsense
  • Filesystem access is justified by PHP profiler functionality

False Positive Considerations

  • Dependency declarations misclassified as security findings
  • Standard npm packages flagged without malicious context

Reviewed 2026-05-23; recommended action: suppress false positive; model confidence 95%.

Open VSX version history

Risk trend by version

24 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
31
Change since first
No change
Change from previous
-18
Versions:
First analyzed version
1.67.18583
Mar 10, 2026
Risk range
31 to 49
Across analyzed versions
Latest analyzed version
1.74.19317
Sep 19, 2026
Selected version
low
Version
v1.74.19317
1 weeks ago
Risk score
31
Findings
23
Change vs previous
-18

Pick any point on the chart to explore that version's code below.

About This Extension

Support for PHP (Xdebug) profiling files and inspecting them.

Frequently Asked Questions