nowfound

Alternatives

Products that do what VSCan does

Detect Malicious VSCode Extensions with AI

  1. 1VD

    Did you know that VSCode extensions run with full access to your system—including file system, network, and credentials? Worse, dozens of malicious extensions have already made it into the marketplace, silently compromising devices. I am a security researcher and student developer who ran into this problem myself. To help tackle this, I built a 100% free tool (no login required) that scans VSCode (and Cursor/Windsurf) extensions for: - Hidden malware and obfuscated code - Dangerous permissions and API misuse - Vulnerable dependencies and suspicious network connections Users have already…

    2025 · vscan.dev

  2. 2

    An open source security scanner for Visual Studio Code

    2020

  3. 3
    Koidex387

    Know if a package, extension, or AI model is actually safe

    Feb 2026 · dex.koi.security

  4. 4

    Track machine learning experiments right in your IDE

    2023

  5. 5

    Police your chrome extensions

    2018

  6. 6

    Search millions of open source repos without leaving the IDE

    2022

  7. 7

    Track browser extension installations / threats in real-time

    2019

  8. 8DU

    Hey HN, I built an automated system that tracks malicious Chrome/Edge extensions daily. The database updates automatically by monitoring chrome-stats for removed extensions and scanning security blogs. Currently tracking 1000+ known malicious extensions with extension IDs, names, and dates. I'm working on detection tools (GUI + CLI) to scan locally installed extensions against this database, but wanted to share the raw data first since maintained threat intelligence lists like this are hard to find. The automation runs 24/7 and pushes updates to GitHub. Free to use for research,…

    Feb 2026 · github.com

  9. 9CG

    There is a growing problem with VSCode extensions: - they're not sandboxed (yet) - just like double-clicking an .exe file - they don't have a permission model - they auto update - they have built-in persistence - they are installed on developer machines with high-value credentials The recent CircleCI and LastPass incidents were both suspected to originate from a compromised developer machine - which is becoming every organization's Achilles heel in terms of cyber posture So I've been working on a way to help mitigate some of these risks Right now, only an MVP of a "CLI" is available: $ code…

    2023

  10. 10DI

    For the past 4 years, I've been tracking the install counts of AI coding extensions in the Visual Studio Code marketplace (GitHub Copilot, Claude Code, OpenAI Codex, etc.) Today, I built an interactive dashboard that lets you see daily install counts for any of them over time. The chart shows GitHub Copilot by default, and you can overlay or swap in any of the other 20+ tools to compare. You can also see important dates in each tool's history (pricing changes, major releases, etc.) and how daily installs changed around those dates. Important caveats: 1) This only tracks VS Code extension…

    Oct 2025 · bloomberry.com

  11. 11

    Bring testing playground into VS Code

    2021

  12. 12

    Scan and secure your code to prevent future cyber threats.

    2025

  13. 13

    Hey HN, I’m Henry, cofounder and CTO at Span (https://span.app/). Today we’re launching AI Code Detector, an AI code detection tool you can try in your browser. The explosion of AI generated code has created some weird problems for engineering orgs. Tools like Cursor and Copilot are used by virtually every org on the planet – but each codegen tool has its own idiosyncratic way of reporting usage. Some don’t report usage at all. Our view is that token spend will start competing with payroll spend as AI becomes more deeply ingrained in how we build software, so understanding how…

    Sep 2025 · code-detector.ai

  14. 14WH

    Hey guys, I'm investing a ton of time on writing unit tests, for both enterprise and personal projects. I came up with the idea to make extension for AI-generated tests and cases within a VS Code. Happy to hear feedback, both positive and negative.

    2024 · marketplace.visualstudio.com

  15. 15
    VScanX11

    Deterministic security scanner with zero false positives

    May 2026 · vscanx.vercel.app

  16. 16
    Vibio12

    Vibio finds security vulnerabilities in your app/codebase.

    Mar 2026 · tryvibio.com

  17. 17

    The best Visual Studio Code extensions collection.

    2025

  18. 18

    Comprehensive web attack surface discovery & analysis

    Sep 2025 · threatscan.ai

  19. 19

    Stop Shipping Buggy Code

    Jan 2026 · securecode.contentkit.studio

  20. 20
    SusCode13

    A VS Code extension that scans for potential security risks.

    2024

  21. 21FL

    Hi HN! We just launched Codacy Guardrails, an IDE extension with a CLI for code analysis and MCP server that enforces security & quality rules on AI-generated code in real-time. It hooks into AI coding assistants (like VS Code Agent Mode, Cursor, Windsurf), silently scanning and fixing AI-suggested code that has vulnerabilities or violates your coding standards, while the code it’s being generated. We built this because coding agents can be a double-edged sword. They do boost productivity, but can easily introduce insecure or non-compliant code. One recent research team at NYU found that 40%…

    2025

  22. 22

    Discover & Solve Domain Vulnerabilities

    2024

  23. 23PM

    Best way I’ve found so far to manage multiple projects in VSCode. Pitch: “ It helps you to easily access your projects, no matter where they are located. Don't miss those important projects anymore.”

    2022 · github.com

  24. 24IM

Ranked by how close each launch is in meaning, then by votes. Refine with your own description →