Tools/Code quality/Security & dependency scanning

Security & dependency scanning for VS Code

63 extensions we classified as Security & dependency scanning, ranked by Marketplace installs. Updated nightly.

ExtensionInstalls / downloads · 7d gain · rating

Provides insights on security vulnerabilities and license compatibility in your application dependencies.

3,164,916+2,994 7d2.6 ★ (32)
234,692+6,524 7d—

Security scanning for your Go, npm, Pypi, Maven and NuGet projects.

95,548+566 7d4.6 ★ (8)
81,097+3,274 7d5.0 ★ (6)

A free security and quality audit tool for modern DevOps teams

70,769+12 7d3.5 ★ (4)
Not listed

Find vulnerabilities, misconfigurations and exposed secrets in your code

60,551+245 7d4.2 ★ (5)
38,199+448 7d—

Tool for a simple usage of GnuPG

48,859+28 7d4.0 ★ (4)
Not listed

Beat vulnerabilities with more-secure code

47,178+415 7d3.7 ★ (6)
36,087+290 7d5.0 ★ (1)
43,056+13 7d2.7 ★ (11)
Not listed

Checkmarx SAST 9.x is a Checkmarx IDE extension that enables scanning/retrieving results on/from Checkmarx CxSAST

35,060+123 7d5.0 ★ (2)
Not listed

Checks if all required NPM packages are up to date

28,289+16 7d—
Not listed

The OpenText™ Application Security Analysis Extension helps developers identify security vulnerabilities by scanning and uploading to OpenText™ Application Security, or running scans through OpenText™ Core Application Security.

25,505+28 7d4.0 ★ (3)
Not listed

GPG Encrypter/Decrypter

22,068+20 7d5.0 ★ (3)
Not listed

Sonatype Nexus IQ Extension for VSCode

20,594+50 7d4.3 ★ (6)
21,720+226 7d—

Checks for known vulnerabilities against the Node Security Project

18,930+6 7d5.0 ★ (1)
Not listed

Secure code as it's written (& generated). In-line security for SAST, secrets, dependencies…

15,125+312 7d5.0 ★ (8)
47,699+1,552 7d5.0 ★ (1)

View npm audit security report in visual format

15,014+18 7d—
Not listed
11,170+36 7d—
Not listed

Get real-time security alerts on your open source dependencies within your Visual Studio Code environment.

11,037+3 7d4.5 ★ (2)
Not listed

Get real-time security alerts on your open source dependencies within your Visual Studio Code environment.

10,419+51 7d3.6 ★ (5)
Not listed

A safety net to help developers safeguard their sensitive information (passwords, API key, tokens, ..) from accidental leaks in their code

10,065+246 7d5.0 ★ (9)
6,846+376 7d5.0 ★ (1)

Bookmark findings and quickly navigate to areas of interest in the codebase

9,240+40 7d4.5 ★ (4)
2,050+56 7d—

Official Sonatype Lifecycle integration

8,292+98 7d5.0 ★ (12)
Not listed

Boost security in your dev lifecycle via SAST, SCA, Secrets & IaC scanning.

7,911+59 7d5.0 ★ (4)
8,203+480 7d—

Scan your code for vulnerabilities with the power of Cortex Cloud.

7,909+35 7d—
2,108+84 7d—

Show security alert for vulnerable dependencies of Node projects

7,667+3 7d—
Not listed

Review and audit analysis results on Fortify Software Security Center from VS Code

5,981+15 7d—
Not listed

Horusec is an open source tool that improves identification of vulnerabilities in your project with just one command.

5,925+6 7d5.0 ★ (1)
1,992+22 7d—

View and resolve security alerts for GitHub repositories, directly from your editor.

5,412+11 7d5.0 ★ (2)
Not listed

Generate OpenSSL secret key for your application

5,335+28 7d—
Not listed

Find security vulnerabilities through functional tests

5,3060 7d5.0 ★ (1)
Not listed

Analyze suspicious VS-based IDE extensions, navigate the extension jungle, and detect harmful code, risky access, and other security vulnerabilities.

5,148+14 7d4.2 ★ (5)
694+30 7d—

OpenPGP Encryption support for VSCode

4,521+9 7d5.0 ★ (2)
Not listed

Security analysis for Ethereum smart contracts

3,960+4 7d—
Not listed

OWASP IDE-VulScanner is an open source IDE plugin tool to analyze an application’s components. It is built on top of OWASP Dependency Check, which scans your application’s component vulnerabilities during implementation phase.

3,944+15 7d5.0 ★ (1)
Not listed

VSCode extension to detect vulnerable regular expressions

3,931+1 7d5.0 ★ (1)
Not listed

Hash text with bcrypt and match with plain text on editor

3,775+7 7d—
Not listed

Displays node package metrics

3,722+2 7d—
Not listed

Provides features for working with MITRE ATT&CK techniques

3,640+2 7d5.0 ★ (1)
Not listed

Visual Studio Code Solidity source code security checker

3,565+4 7d—
Not listed

Dependency cleaner is handy extension for Visual Studio Code which removes unused dependencies from your project

3,469+1 7d5.0 ★ (1)
Not listed

Find and fix security issues in your code

3,246+45 7d5.0 ★ (3)
22,665+1,664 7d5.0 ★ (9)

Dependency update checker for npm, yarn, pnpm. Find outdated packages, update versions easily.

3,220+6 7d5.0 ★ (3)
3,190+71 7d—

Standalone realtime security scanners - AI Secure Coding, OSS, Secrets, IaC, and Containers

2,969+106 7d4.0 ★ (1)
7,536+124 7d—

A plugin to incorporate Static and SCA findings from Veracode Application Profiles

2,955+3 7d—
Not listed

This extension will help you make sure your local npm/yarn packages are not out of date with the package.json specified versions.

2,4900 7d—
Not listed

Increase your code’s security with advanced Static Application Security Testing (SAST)

2,179+37 7d—
2,846+210 7d—

Visualize the dependancy graph of your project with a click of a button, explore vulnerabilities

2,005+5 7d—
Not listed

DigitSec Extension to analyze Salesforce code and configs for Cursor and VS Code

1,956+10 7d5.0 ★ (3)
Not listed

A VS Code extension provided by Clutch Security to scan the workspace for secrets using Gitleaks

1,900+27 7d—
Not listed

An extension that helps you avoid leaking anything

1,838+4 7d5.0 ★ (2)
Not listed

VirusTotal checker in VSCode

1,816+7 7d—
Not listed

Mask secrets in .env files while streaming

1,645+26 7d5.0 ★ (2)
Not listed

Integrates Harness SAST and SCA into your editor.

1,561+6 7d5.0 ★ (2)
Not listed

Corridor secures your AI-generated code.

1,435+17 7d—
20,492+1,092 7d—

Runs credential digger scan

1,326+8 7d—
Not listed

OpenText™ Fortify Code Security Extension for VS Code helps developers identify and remediate security issues directly in the editor. Run scans, review issues at source, and use AI-assisted fixes with guided explanations to resolve vulnerabilities faster and build high-quality code

1,314+60 7d5.0 ★ (5)
324+64 7d—

Simple source code security audit helper

1,3130 7d—
Not listed

Converts characters from one encoding to another using a transformation. This tool will help you encode payloads in testing sql injections, XSS holes and site security.

1,299+3 7d5.0 ★ (1)
Not listed

Encrypt/Decrypt files using SOPS

1,287+1 7d—
Not listed

Tenable.cs scans your Infrastructure as Code (IaC) for possible vulnerabilities and mitigates risks before the infrastructure is provisioned.

1,093+1 7d5.0 ★ (3)
Not listed

Generate Visual NPM Package Audit Report.

1,087+1 7d—
Not listed

GPG Encrypter/Decrypter/Sign

1,0850 7d—
Not listed

This plugin runs the OWASP Dependency-Check tool. Based on the results that OWASP Dependency-Check provides, it generates the results.

1,040+3 7d—
Not listed

Use ChatGPT to find vulnerabilities in your code.

1,020+2 7d—
Not listed
Showing all 63VSXRank’s own grouping, not a Marketplace rank.
63 listings