extcheckearly, free

Check your team's VS Code extensions

Paste code --list-extensions, a repo's .vscode/extensions.json or devcontainer.json, or name a public GitHub repo. You get back what Microsoft has flagged, IDs that don't exist, and names anyone could claim on Open VSX, the registry Cursor, Windsurf and VSCodium install from.

Get your list: code --list-extensions (or cursor --list-extensions). Versions from --show-versions are fine.

Runs in your browser. Extension IDs go straight to the VS Code Marketplace and Open VSX. Two lookups Microsoft doesn't allow from browsers (its block list, and publisher pages for IDs that aren't on the Marketplace) go through this site's server. Nothing is stored.

What it checks

Microsoft's own block lists

The list VS Code downloads to uninstall malicious extensions and stop installs of deprecated ones. A repo can keep recommending them for years.

Names someone else could claim

An ID that isn't on the Marketplace, or whose namespace doesn't exist on Open VSX, installs whatever gets published under it first. Pluto Security found 150 squatted extensions on Open VSX in July 2026.

Stale and just-updated

Extensions with no release in 3+ years are the ones that get sold or taken over. A release in the last few days reaches every machine within hours. GitHub was breached through one in May 2026.

Not checked: what each extension does at runtime, and Chrome or Edge extensions. It's a quick check, not an audit.