Unverified Publisher
Flags items published by entities that haven’t gone through the publisher verification process of the marketplace. Lack of verification may indicate higher risk, as the publisher’s identity and trustworthiness are unconfirmed.
Item description not available.
Flags items published by entities that haven’t gone through the publisher verification process of the marketplace. Lack of verification may indicate higher risk, as the publisher’s identity and trustworthiness are unconfirmed.
Flags items that are not maintained on the marketplace, suggesting concerns about the item's reputation and the publisher's reliability.
Flags publishers that publish only one item on the marketplace, suggesting concerns about the publisher's reliability.
AI-powered analysis of the extension's source code for security insights and risk assessment.
This code is a Visual Studio Code extension plugin named "FC WebIDE Plugin" designed to configure the IDE environment based on environment variables and user context. It primarily performs the following actions:
WEBIDE_WORKSPACE_TYPE is set to "oss".MQ_QUICK_START_IDE_DEMO, it either prepares a quick start configuration for Java development or loads default code files.FcWebIDE.runJava that runs the active Java file with a check for placeholder Aliyun Access Keys, warning the user if they are not replaced.fs/promises API to check file access and rename files.vscode.commands.registerCommand("FcWebIDE.runJava", () => {
const editor = vscode.window.activeTextEditor;
if (editor) {
const { document } = editor;
let fileContent = document.getText();
if (fileContent.includes('ACCESS_KEY = "YOUR_ALIYUN_ACCESS_KEY_ID"') ||
fileContent.includes('SECRET_KEY = "YOUR_ALIYUN_ACCESS_KEY_SECRET"')) {
vscode.window.showWarningMessage("Please replace the ACCESS_KEY and SECRET_KEY in the code with your Aliyun AK and SK first.", { modal: true });
return;
}
}
vscode.commands.executeCommand("java.debug.runJavaFile");
});
No network communications, process executions beyond VSCode commands, obfuscation, or persistence mechanisms were detected.
API calls detected through static analysis of the source code. For more accurate insights, explore our sandbox dynamic analysis.
Any encoded/decoded secrets we managed to find in the source code, git repository, or related files
Known vulnerabilities and security issues detected in the extension's dependencies and code.
Any identifiers we detected that may indicate external communication from the item's code
Dependencies and third-party libraries used by the extension, including version information and license details.