Every finding names the file, the line, and the request that triggered it.
Every extension and package runs the full battery: vulnerability and secret-leak testing, static and dynamic analysis, AI code analysis. Findings come back in one evidence format, naming the file, the change, why it is dangerous, and what to do next.
npm package
Attackers ship the payload in an update, not the version you installed.
Every update is compared against the version before it. A release that scored clean and now scores critical is band escalation, and the diff names the change that caused it.
- + New exfiltration channels introduced on update
- + Added permissions and weakened content policy
- + New remote-code paths that evade review
Update lineage
- 1.4.0reviewed on release
- 1.4.1no change to permissions or hosts
- 1.4.2new outbound host in background.js:214
- 1.4.3not published yet
The package executes in a throwaway VM, and every host it contacts is recorded.
Extuno executes the real extension or package in an ephemeral, network-segmented micro-VM and records exactly what it does.
- + Network endpoints and outbound payloads
- + Credential, session, and wallet theft
- + Crypto-miners and covert command traffic
1100+ rules read the code. One score, and every point traces to the rule that added it.
Capability abuse, remote code, credential theft, evasion, surveillance, covert command traffic, obfuscation. That is what the rules look for, on every version.
- + Severity-banded: clean, review, critical
- + A rule that fires returns a file path, a line number, and the matched snippet
- + Exportable as SARIF, or a non-zero exit from the CI gate
A clean extension can still ship an exploitable bug.
An exploitable release does not have to be a malicious one. Extuno tests each version for vulnerable code paths and dependencies with known CVEs, and reports them whether or not anyone put them there on purpose.
- + Unsafe API and injection-prone patterns
- + Vulnerable and outdated dependencies
- + Every finding mapped to its location and fix
It reads every version in full, then compares what the other layers found.
An analysis layer reads the complete source of every version and correlates it with the static and dynamic results. It clusters related findings and matches code against known-malware behavior. Behavior that does not appear in the package's earlier versions is flagged as an anomaly.
- +
AI review is advisory. It reads the source and explains a finding, but it never changes a verdict or a gate result - the rule engine and the sandbox decide.
Reads the full source code of every version - + Anomaly flags against prior versions
- + Known-malware similarity and campaign clustering
- + Every flag links back to its evidence
A pass/fail check on every pull request.
1000+ anchored secret detectors test extensions and packages for leaked keys, tokens, and credentials. Point them at your own repos too. Findings come back as SARIF, with git-history scanning and baseline support.
- + Standard SARIF output for code scanning
- + Git-history and baseline support
- + GitHub and GitLab pipelines
A monitor re-scans when the published version actually changes, not on a timer.
Add extensions and packages to a watchlist and route findings to the channels your team already uses.
Watchlist
Track any extension or package across all twelve ecosystems.
Alert lifecycle
Alerts move from open to acknowledged to resolved. The audit trail records every change.
Delivery
SIEM, Slack, Teams, PagerDuty, email, and signed webhooks.