Security tool that checks packages, extensions, and AI models for safety before installation
Scores risk using static and behavioral signals across npm, VS Code, JetBrains, and Hugging Face
Free IDE extension scans installed extensions in real time — no setup required
Pricing: Free forever
Best for: Individuals & startups
Pros & Cons
Pros
Catches risky packages and extensions before they enter your stack
Covers multiple ecosystems: npm, VS Code, JetBrains, Hugging Face
Real-time background scanning flags issues without interrupting workflow
Built by the team that discovered GlassWorm, ShadyPanda, and PhantomRaven attacks
Cons
Risk scoring may produce false positives for legitimate but unusual packages
New tool with evolving detection capabilities
Limited to supported ecosystems — does not cover all package managers
Preview
Key Features
Risk scoring for packages, extensions, and AI models before installStatic and behavioral signal analysis including obfuscation detectionIDE extension for real-time background scanning in Cursor, Windsurf, VS CodeCovers npm packages, VS Code/JetBrains extensions, and Hugging Face modelsPublisher and dependency signal evaluationFree with no setup or account required
Koidex helps developers check whether packages, browser extensions, and AI models are safe before installing them. It scores risk using static and behavioral signals: permissions, suspicious patterns like obfuscation, dependency and publisher signals, and known bad indicators. Koidex scans across VS Code, JetBrains, npm, and Hugging Face. The IDE extension runs background scans on installed extensions in Cursor, Windsurf, and VSCodium, flagging risky installs in real time. Free with no setup required.
Koidex is a security tool that checks packages, browser extensions, and AI models for safety before you install them. It scores risk using static and behavioral signals like permissions, obfuscation, and publisher reputation.
Which ecosystems does Koidex cover?
Koidex scans npm packages, VS Code and JetBrains extensions, and Hugging Face AI models. The IDE extension runs background scans in Cursor, Windsurf, VS Code, and VSCodium.
Is Koidex free?
Yes. Koidex is completely free with no setup or account required. Install the IDE extension to start scanning your installed extensions and packages in real time.