Security Findings
9No tagged releases
SuspiciousLineageRepo ships no git tags and no GitHub releases — consumers cannot pin to stable, reviewable versions
Publisher cannot be tied to the declared repo
SuspiciousLineageThe declared source repository could not be tied to this publisher: the registry namespace does not match the repo owner, the namespace is not verified, and no Marketplace twin corroborates it. Repo lineage is not shown, because it would describe a repository this publisher may not own.
Hardcoded secrets/API keys
SuspiciousScannerSecret Keyword: ****
dist/views/configureSolution.js
Hardcoded secrets/API keys
SuspiciousScannerSecret Keyword: ****
dist/views/createSolution.js
Hardcoded secrets/API keys2×
SuspiciousScannerSecret Keyword: ****
Secret Keyword: Enter...****
dist/views/configWizard.js
Hardcoded secrets/API keys
SuspiciousScannerSecret Keyword: ****
dist/views/manageSolution.js
Hardcoded secrets/API keys
SuspiciousScannerSecret Keyword: ****
dist/views/manageComponentsPacks.js
Transitive delivery to an unrelated extension
SuspiciousScannerPulls unrelated extension(s) via extensionPack/Dependencies (payload lives in the target): redhat.vscode-yaml, llvm-vs-code-extensions.vscode-clangd