Browser extensions · IDE plugins · Browser & IDE context

Extension security across your organisation.

Discover browser extensions and IDE plugins across your fleet, understand their security posture, and take evidence-backed action.

The ExtVerdict Portal overview for a demo organisation: fleet reporting, what needs attention, and extension counts.
ExtVerdict Portal overview. Demo organisation, synthetic data.

Visibility

Extensions run with real access, across every team.

Browser extensions are installed by people in every role, not just engineering. IDE plugins sit next to source code, credentials and build tooling. Both change quietly: new installs, new versions, new permissions.

Across many machines, profiles and products, it is hard to answer simple questions. What is installed, where, and at which version? What can it access? Is anything known to be vulnerable, and what should happen next?

How it works

From inventory to evidence-backed action.

ExtVerdict separates what is observed, what is known about it, and what you decide to do.

  1. Step 1

    Discover

    The ExtVerdict Agent reports installed extensions and plugins, and the browsers and IDEs they run in, from each machine.

  2. Step 2

    Assess

    ExtVerdict applies heuristic review today, with vulnerability intelligence and browser & IDE context rolling out, keeping each source visible.

  3. Step 3

    Act

    As remediation guidance rolls out, you get source-backed guidance for the action that fits, carried out through your own management workflow.

  4. Step 4

    Verify

    A later scan confirms the outcome from endpoint evidence. Nothing is marked resolved by hand.

Capabilities

What ExtVerdict brings together.

Each result carries its evidence and source. Unknown is shown as unknown, never as safe.

Fleet inventory

Every browser extension and IDE plugin, per machine, profile and product, with its version and, where the platform exposes them, permissions and enabled state. Changes between scans are kept as history.

Risk evidence

A heuristic risk level for each extension, with the specific reasons behind it. It is labelled as review signals, never presented as confirmed threat intelligence.

Vulnerability intelligence

Rolling out

Built to match known advisories to the exact extension identity and version from trusted sources. Rolling out first for VS Code-family and Firefox extensions; everywhere else reads as not covered, never as clean.

Browser & IDE context

In development

The browser or IDE each extension runs in: its installed version and release channel, compared with official vendor releases and security advisories where a trusted source exists. Part of the intelligence layer ExtVerdict is building next.

Findings

Extension findings carry their evidence, source and freshness today, so a result can always be traced back to why it exists. Browser and IDE findings join them as that part of the product develops.

Remediation guidance

Rolling out

A recommended action with exact steps for the management tool you already use, what it does to existing and future installations, how to roll back and how to verify. Rolling out across supported platforms.

Coverage

Browsers and IDEs, in one inventory.

ExtVerdict inventories extensions and plugins, and the browsers and IDEs they run in, across these products.

Browsers

Extensions in every browser profile, with permissions and enabled state where the browser exposes them.

  • Google Chrome
  • Microsoft Edge
  • Mozilla Firefox
  • Brave

VS Code family

Extensions per editor, including forks that share the VS Code extension format.

  • VS Code
  • VS Code Insiders
  • Cursor
  • Windsurf
  • VSCodium

JetBrains IDEs

User-installed plugins per IDE product and configuration.

  • IntelliJ IDEA
  • PyCharm
  • WebStorm
  • GoLand
  • PhpStorm
  • Rider
  • CLion
  • DataGrip
  • Android Studio
  • RustRover

Browser extensions are read from each browser's stable channel. Vulnerability intelligence and browser & IDE security context are rolling out for a narrower, source-dependent set of products; everything else is labelled not covered.

The ExtVerdict Portal extension inventory table for a demo organisation: one row per extension with its platform, publisher, products, versions and top review reason.
The extension inventory in the ExtVerdict Portal: every extension across browsers and IDEs, with publisher, products, versions and the top review reason. Demo organisation, synthetic data.

Security

Read-only by design.

The ExtVerdict Agent observes and reports. It does not uninstall software, modify policy or execute remote commands. Remediation stays in your approved management workflows.

How ExtVerdict handles security

The Agent does

  • Reads installed browser extensions and IDE plugins
  • Reads installed browser and IDE versions
  • Reports to your organisation's ExtVerdict tenant over HTTPS

The Agent does not

  • Uninstall or disable software
  • Change browser, IDE or device policy
  • Execute remote commands
  • Open a remote shell
  1. ExtVerdict AgentObserves and reports
  2. ExtVerdictAnalyses, adds intelligence and prepares guidance
  3. Your management toolsCarry out remediation you approve

Remediation

Guidance you can act on, in the tools you already run.

Turn findings into clearer next steps, with source-backed remediation guidance rolling out across supported platforms. For a finding, ExtVerdict recommends an action and shows exactly how to carry it out through your approved management workflow. Disabling, blocking and removing are different outcomes, and they differ by browser and tool, so every recipe states its effect before its steps.

  1. Update

    Move to a version that no longer matches the advisory.

  2. Disable

    Stop it running while it stays installed.

  3. Remove

    Remove the existing installation from a machine or profile.

  4. Block future installation

    Use the browser's or IDE's own policy to prevent it being installed again.

  5. Verify

    Confirm the result on the next scan, from what the endpoint reports.

Guidance is written for

  • Manual steps on the machine
  • Group Policy
  • Microsoft Intune
  • Jamf Pro
  • Kandji
  • Google Admin console
  • JetBrains IDE Services
  • BeyondTrust EPM

ExtVerdict does not connect to or change these tools. You apply the guidance; a later scan verifies the result.

In the Portal

Every recommendation shows its working.

Recommendations in the ExtVerdict Portal follow one structure, so they can be reviewed before anyone acts on them.

Evidence
What the recommendation is based on: a malicious-extension listing, a known advisory or heuristic review.
Recommended action
The action that fits the evidence, with the reasons for it.
Effect
What happens to the existing installation, to future installation and to execution.
Steps
Exact steps for the chosen management tool, with a copyable value where one applies.
Rollback
How to reverse it without disturbing other policy entries.
Verification
How the outcome is confirmed from endpoint evidence on a later scan.
Sources
The official vendor documentation behind the recipe, with the date it was checked.
Schematic of the fields in each remediation recommendation in the ExtVerdict Portal. No customer data is shown.

See ExtVerdict on your fleet.

Talk to us about your browsers, IDEs and management tooling. We'll show you what ExtVerdict finds and how it explains it.