VSCan
Analyzes VS Code extensions for security vulnerabilities, permissions, and supply chain risks, providing a scored report with recommendations.
VSCan is a security analysis tool for Visual Studio Code extensions, identifying vulnerabilities and risks before installation. It serves developers, IT teams, and security teams in organizations of all sizes. The tool combines static code analysis, publisher trust signals, and external threat intelligence to deliver a comprehensive risk report, differentiating itself by providing automated security transparency for the VS Code ecosystem.
Key features
- Deep code analysis (AST-level)
- Detects command injection and unsafe eval
- Checks for weak cryptography and obfuscation
- Vets publisher identity and install counts
- Audits dependencies against GitHub Advisory
- Cross-references VirusTotal and secret-scanning
- Network profiling for threat intelligence
- Provides risk score and categorized evidence
- No social media activity within the last 30 days
GTM channels
- API
- Docs
ICP
- Software developers
- IT teams
- Security teams