Local-first extension security

Know what your editor extensions can reach.

ExtGuard audits installed VS Code extensions for leaked credentials, risky capabilities, and known malicious IDs. Free scans stay on your machine.

What it checks

Useful evidence, not noisy accusations

01

Permission auditing

Reviews manifests for workspace trust posture, eager activation, and powerful editor integrations.

02

Secret scanning

Detects credential-shaped values without storing or displaying the secret itself.

03

Threat matching

Checks installed extension IDs against a threat snapshot shipped inside the extension.

04

Clear risk context

Separates expected capability from concrete findings and shows the evidence behind each score.

Simple pricing

Start locally. Add Team only when you need it.

Free

$0 forever

  • Local extension scanning
  • Risk dashboard sidebar
  • Manual scans and VSIX checks
  • Bundled malicious extension data
  • VS Code-compatible editors
Install free

Team

$9 per seat, monthly

Optional
  • Everything in Free
  • Seat-based license activation
  • Opt-in sanitized report upload
  • Subscription management through Stripe
  • No source code or secret values uploaded

Checkout and card handling are hosted by Stripe. ExtGuard never receives your card number.

A deliberate boundary

The scanner stays local.

Team reporting is separate, off by default, and available only after license activation. Reports contain extension identifiers and summarized risk results. They do not contain source code, secret values, or absolute file paths.