What a VS Code verified publisher badge means, compared with Open VSX →
Checks your SECURITY.md, disclosure policy or incident runbook against the EU Cyber Resilience Act reporting clock that started on 11 September 2026: 24-hour early warning, 72-hour notification, 14-day final report, to ENISA and your coordinating CSIRT. 18 checks. Runs offline.
Daily readings on both stores, taken by us. As of 25 Sept 2026.
Each bar is one day’s change in the store’s own counter. Open VSX counts a download on every update, so a day includes updates by people who already had it.
Positions observed daily on both stores. Neither store publishes this, and the two run separate search engines over separate catalogues.
| Search | Marketplace | Open VSX |
|---|---|---|
| markdown | — | #898of 1,096↑60 7d |
| security | #603of 1,406↑348 7d | #319of 431 |
2 more searches, day-by-day history, and the extensions ranked above it. See plans | ||
VS Code Marketplace search ranking: measuring jitter and real movement →
14 releases · first published Sept 2026
Why the Open VSX download count looks inflated →
Downloads count every update, not unique installs.
Vulnerability Report Lint - CRA 24h/72h/14d timeline (Article 14)’s own readme, changelog and license, as published to the VS Code Marketplace.