Security & dependency scanning for VS Code
63 extensions we classified as Security & dependency scanning, ranked by Marketplace installs. Updated nightly.
Provides insights on security vulnerabilities and license compatibility in your application dependencies.
Security scanning for your Go, npm, Pypi, Maven and NuGet projects.
A free security and quality audit tool for modern DevOps teams
Find vulnerabilities, misconfigurations and exposed secrets in your code
Beat vulnerabilities with more-secure code
Checkmarx SAST 9.x is a Checkmarx IDE extension that enables scanning/retrieving results on/from Checkmarx CxSAST
Checks if all required NPM packages are up to date
The OpenText™ Application Security Analysis Extension helps developers identify security vulnerabilities by scanning and uploading to OpenText™ Application Security, or running scans through OpenText™ Core Application Security.
Sonatype Nexus IQ Extension for VSCode
Checks for known vulnerabilities against the Node Security Project
Secure code as it's written (& generated). In-line security for SAST, secrets, dependencies…
Get real-time security alerts on your open source dependencies within your Visual Studio Code environment.
Get real-time security alerts on your open source dependencies within your Visual Studio Code environment.
A safety net to help developers safeguard their sensitive information (passwords, API key, tokens, ..) from accidental leaks in their code
Bookmark findings and quickly navigate to areas of interest in the codebase
Official Sonatype Lifecycle integration
Boost security in your dev lifecycle via SAST, SCA, Secrets & IaC scanning.
Scan your code for vulnerabilities with the power of Cortex Cloud.
Show security alert for vulnerable dependencies of Node projects
Review and audit analysis results on Fortify Software Security Center from VS Code
Horusec is an open source tool that improves identification of vulnerabilities in your project with just one command.
View and resolve security alerts for GitHub repositories, directly from your editor.
Find security vulnerabilities through functional tests
Analyze suspicious VS-based IDE extensions, navigate the extension jungle, and detect harmful code, risky access, and other security vulnerabilities.
OpenPGP Encryption support for VSCode
OWASP IDE-VulScanner is an open source IDE plugin tool to analyze an application’s components. It is built on top of OWASP Dependency Check, which scans your application’s component vulnerabilities during implementation phase.
VSCode extension to detect vulnerable regular expressions
Hash text with bcrypt and match with plain text on editor
Provides features for working with MITRE ATT&CK techniques
Dependency cleaner is handy extension for Visual Studio Code which removes unused dependencies from your project
Find and fix security issues in your code
Dependency update checker for npm, yarn, pnpm. Find outdated packages, update versions easily.
Standalone realtime security scanners - AI Secure Coding, OSS, Secrets, IaC, and Containers
A plugin to incorporate Static and SCA findings from Veracode Application Profiles
This extension will help you make sure your local npm/yarn packages are not out of date with the package.json specified versions.
Increase your code’s security with advanced Static Application Security Testing (SAST)
Visualize the dependancy graph of your project with a click of a button, explore vulnerabilities
DigitSec Extension to analyze Salesforce code and configs for Cursor and VS Code
A VS Code extension provided by Clutch Security to scan the workspace for secrets using Gitleaks
An extension that helps you avoid leaking anything
Integrates Harness SAST and SCA into your editor.
Runs credential digger scan
OpenText™ Fortify Code Security Extension for VS Code helps developers identify and remediate security issues directly in the editor. Run scans, review issues at source, and use AI-assisted fixes with guided explanations to resolve vulnerabilities faster and build high-quality code
Converts characters from one encoding to another using a transformation. This tool will help you encode payloads in testing sql injections, XSS holes and site security.
Tenable.cs scans your Infrastructure as Code (IaC) for possible vulnerabilities and mitigates risks before the infrastructure is provisioned.
This plugin runs the OWASP Dependency-Check tool. Based on the results that OWASP Dependency-Check provides, it generates the results.
Use ChatGPT to find vulnerabilities in your code.