Extension Security

The security check before you click Install.

Downloads and ratings tell you what's popular. GuardRails shows you what you're installing—before it reaches your editor.

marketplace / extension / 1.8.11 Published
T
SELECTED EXTENSIONtrivy-vulnerability-scanner@1.8.11
Package identity resolved Release contents mapped Important behavior grouped
GUARDRAILS RESULTtrivy-vulnerability-scanner@1.8.11
Current
WHAT NEEDS YOUR ATTENTION

Worth a closer look

The extension exposes sensitive capabilities or non-confirmed risk evidence that needs context.

Exact release Evidence available
Open public report
Marketplace scale~0

extensions compete for a place inside developer environments.

~1,800from verified publishersAbout 1 in 33
3.3 billioninstalls across the marketplace

Industry figures, with sources and context below.

See the product

See the extension behind the listing.

GuardRails turns an extension package into a decision you can understand. Start with the answer, then open the evidence when you need it.

guardrails.app / inspection Public intelligence
01 · Select

Start with the extension you want.

Search by name, publisher ID, or Marketplace link. GuardRails keeps the chosen release in view.

trivy-vulnerability-scanner
T
EXACT MATCHtrivy-vulnerability-scanner@1.8.11

The selected identity and release stay attached to the report.

Releases change

The name stays the same. The behavior may not.

GuardRails keeps the previous release in view, so a meaningful new capability does not disappear inside an ordinary update notification.

Compare extension releases
Release comparisonIllustrative change view
Version 1.3Previously reviewed
  • Reads project files
  • Provides editor commands
Version 1.4New release
  • Reads project files
  • Runs terminal commands New
  • Opens network connections New
Why check first

The marketplace grew. So did the reasons to look closer.

Most extensions are useful. The scale of the ecosystem simply makes downloads and ratings an incomplete security signal.

VS Code malware detectionsFirst 10 months of 2025
27Earlier count
105Later count

Nearly in ten months

And one incident reached1.5 million

installs across two AI extensions reported to be silently exfiltrating source code.

From public analysis

A result worth opening.

One current GuardRails result, tied to the analyzed release—not a fictional marketing alert.

Recent finding
aquasecurityofficial.trivy-vulnerability-scanner

trivy-vulnerability-scanner

@1.8.11

The extension exposes sensitive capabilities or non-confirmed risk evidence that needs context.

View exact report
Keep watching

The first check is only the beginning.

When a new release changes what an extension can do, GuardRails brings that decision back into view.

Explore monitoring
GuardRails

Make every extension a decision—not a guess.

Search public extension intelligence before the next install, then keep watching what changes.