Recommended Free Tools
A VSIX is the installable package produced by vsce package, so it—not just the source repository—is the important boundary to check before distribution. Microsoft documents scans for .env files during VSCE packaging and secret detection for newly published Marketplace extensions, but those safeguards are not documented as a guarantee that every credential in every packaged file will be found. Inspect the release artifact and prevent developer credentials from entering it in the first place.
What a VSIX contains—and why packaging matters
VSCE (Visual Studio Code Extensions) is Microsoft’s command-line tool for packaging, publishing, and managing extensions. Running vsce package from an extension’s root creates a .vsix file. VS Code supports using VSIX files for testing, distribution outside the Marketplace, and private sharing; users can install them through the Extensions view or the command line. See Microsoft’s extension publishing guide.
As an Amazon Associate I earn from qualifying purchases.
The package is what an installer receives. A source-tree review alone does not establish what generated files or other included content made it into that distributable. Packaging options, platform-specific builds, and VSCE versions can affect the artifact, so use the command and build setup appropriate to the extension rather than assuming one universal packaging invocation.
Separate shipped credentials from user-provided secrets
There are two different security questions: whether a credential is embedded in files distributed to every installer, and how an extension safely stores a secret after a user supplies it. The first is a packaging and release-hygiene problem. A key placed in JavaScript, configuration, generated assets, or another shipped file may be recoverable by examining the package.
#1 Best Overall
For runtime secrets supplied to an extension, VS Code’s API guidance recommends SecretStorage. It warns against storing passwords or secrets in ExtensionContext.workspaceState or globalState, which store data in plaintext. Microsoft’s remote extensions documentation covers this storage guidance. SecretStorage helps with a user’s runtime secret; it does not make a developer credential safe to bundle into the extension.
What VS Code’s built-in checks cover
Microsoft’s extension runtime security documentation describes two relevant secret checks:
Rank #2
- VSCE scans
.envfiles during packaging and blocks publishing if secrets are found. - The Marketplace scans each newly published extension for secrets such as API keys or credentials and blocks publication if it detects them.
These statements describe the documented checks, not proof that all files, compiled bundles, or credential types are covered. The same documentation discusses malware scanning and extension signature verification; those address malware screening and package integrity or source verification, not whether a package is free of secrets.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
A practical pre-release check for the actual artifact
Because the VSIX is the distributable, checking it is a sensible additional release step. This is workflow guidance, not a Microsoft-mandated inspection command.
Rank #3
- Build and package as intended. Use the extension’s real release configuration and platform target, then create the VSIX with the appropriate VSCE workflow. Microsoft’s publishing workflow documentation describes VSCE packaging and publishing options.
- Review the package contents. Check the files included in the VSIX, including generated output and configuration, for credentials that should not ship. Confirm that files excluded from source control or local development have not reappeared in a build or packaging step.
- Run secret checks against release content. Treat the documented
.envscan and Marketplace scan as useful safeguards, not substitutes for reviewing the package contents and build output. - Verify the revised package. After removing or relocating a credential, build a fresh VSIX and check that artifact rather than relying on a source edit or an earlier package.
Managed environments do not remediate a packaged secret
Organizations can govern which extensions are installable. Microsoft’s enterprise guidance documents allow and block controls by publisher, extension, version, and platform, with support starting in VS Code 1.96. These controls help manage distribution in an organization; they do not remove a credential from an extension package. Details are in Microsoft’s enterprise extensions guide.
Quick Recap
Best Value
Rank #4
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




