FAQ

Answers, in plain terms.

Common questions about what Extuno detects, how it scans, and how to start.

What does Extuno actually detect?
Extuno catches supply-chain risk in browser extensions and developer packages. The case it is built for is an update that turns a clean version malicious. It diffs each version against the one before it and reports the exact change, why it is dangerous, and the recommended action.
Which ecosystems are covered?
Twelve: Chrome and Firefox extensions; VS Code, Open VSX, JetBrains, and Eclipse plugins; Discord client mods; and npm, PyPI, Composer, Maven, and WordPress packages. Every result uses the same evidence format.
What are the three scan layers?
Static analysis reads the code without running it, using 1100+ rules. The dynamic sandbox runs the real artifact live in a network-segmented micro-VM and records its behavior. AI analysis reads the full source of every version, correlates both, and flags anomalies against the package's own history.
How is the free trial structured?
5 free credits on signup. One credit per scan, no card required. One credit runs one scan, including static, dynamic, and AI analysis with full evidence.
Does the browser companion cost anything?
No. The companion is free. It scans installed extensions, runs a server-side deep scan, and blocks malicious sites, trackers, miners, phishing, and dangerous downloads.
Can Extuno run in CI?
Yes. The CI gate runs 1000+ anchored secret detectors with SARIF output and a pass/fail check on every pull request, with git-history and baseline support for GitHub and GitLab.
Is a Chrome extension I installed safe?
Open Extuno or the free browser companion. It checks each installed extension against the threat database and a known-malicious catalog and runs a live deep scan of the published package, returning a clean, suspicious, or malicious verdict with the evidence behind it. A popular, long-standing extension is still worth checking, because the danger is often a later update, not the first release.
Which browser extension permissions are risky?
Broad host access (all sites), cookies, scripting, webRequest, debugger, nativeMessaging, and proxy give an extension deep reach into pages, sessions, and network traffic. Extuno maps the permissions an extension requests against the ones it actually uses at runtime and flags dangerous combinations. See our guide on browser extension permissions.
How do you scan an npm package?
Extuno downloads the published tarball, reads it statically with 1100+ rules (install-script execution, obfuscation, leaked secrets), runs it in a network-segmented sandbox to capture what it contacts and sends, reviews the source with AI, and diffs it against the prior version. See npm package security.
How do you scan a PyPI package?
The same pipeline as npm: a static read of the sdist or wheel including setup.py install-time code, a sandbox run, an AI review, and a version diff. Install-time code that reaches the network or reads credentials is flagged with evidence. See PyPI package security.
What is version diffing and why does it matter?
Version diffing compares a new release against the one it replaces and reports the security-relevant delta: a new exfiltration host, an added dangerous permission, fresh obfuscation, a weakened content security policy, or new remote code. It is how an extension or package that was clean for months but poisoned in an update gets caught.
Can an extension steal my cookies or session?
Yes. An extension with cookie or broad host access can read session cookies and authorization headers and send them to a server. Extuno follows cookie and auth data to network sinks, and the sandbox records the actual request and payload, so a theft flow is shown with evidence rather than a bare permission warning.
What is typosquatting?
Typosquatting is publishing a malicious package under a name close to a popular one (a swapped letter, an added hyphen, a scope change) so a typo installs it. Extuno flags name similarity to well-known packages and scans the package itself for install-time and runtime malice.
What is dependency confusion?
Dependency confusion tricks a build into pulling a public package instead of an intended internal one with the same name. Extuno scans the resolved package for install-script execution, network calls, and secret access, and version-diffs it. Pin and scope internal names, and gate installs with the CI check.
What is slopsquatting?
Slopsquatting is registering package names that AI coding tools tend to hallucinate, so a suggested but nonexistent import resolves to an attacker's package. Treat every new dependency as untrusted: Extuno scans it for install-time and runtime behavior before it ships, and the CI gate blocks a malicious one.
Do you scan VS Code extensions?
Yes. A VS Code extension is analyzed statically and in the sandbox, because it runs with the developer's privileges and can execute commands and reach the network. JetBrains and Eclipse plugins are covered as well. See IDE extension security.
How is Extuno different from an online file-reputation scanner?
An extension update published an hour ago has no reputation to look up. The lookup comes back empty and you still do not know what the new code does. Extuno does not wait for a prior sighting. It reads the code, runs the artifact in a sandbox, diffs it against the version it replaced, and shows the evidence for each finding.
How is Extuno different from a vulnerability database lookup?
Advisories get written after somebody investigates. A package published this morning to steal your registry token has no entry yet, and may never get one. Extuno reads the artifact and diffs it against the previous release. Nobody has to file anything first.
How is Extuno different from a dependency (SCA) tool?
An SCA tool tells you which of your libraries have a published vulnerability. It cannot tell you that a package which is fully up to date is also malware. Extuno runs the artifact in the sandbox, reads its install-time code, checks it for leaked secrets, and diffs it against the previous release. Malicious and poisoned packages get caught, not just vulnerable ones.
How is Extuno different from a secret-only scanner?
Extuno runs 1000+ anchored secret detectors, so leaked keys are covered. The same scan also looks for malicious code, checks which permissions the artifact demands, spots obfuscation, and watches the traffic it sends at runtime. Any of that can fail the CI gate. Secret detection is one layer, not the whole product.