Is Github.Vscode Codeql Safe?
Use Github.Vscode Codeql with some caution. Github.Vscode Codeql is a VS Code extension with a Nerq Trust Score of 57.5/100 (C), based on 3 independent data dimensions. It is below the recommended threshold of 70. Security: 90/100. Popularity: 75/100. Data sourced from VS Code Marketplace metadata, publisher verification, installs, and ratings. Last updated: 2026-03-25. Machine-readable data (JSON).
Is Github.Vscode Codeql safe?
CAUTION — Github.Vscode Codeql has a Nerq Trust Score of 57.5/100 (C). It has moderate trust signals but shows some areas of concern that warrant attention. Suitable for development use — review security and maintenance signals before production deployment.
Trust Score Breakdown
Key Findings
Details
| Author | GitHub |
| Category | vscode |
| Source | N/A |
Github.Vscode Codeql Across Platforms
Same developer/company in other registries:
Safety Guide: Github.Vscode Codeql
What is Github.Vscode Codeql?
Github.Vscode Codeql is a VS Code extension — CodeQL for Visual Studio Code.
How to Verify Safety
Check marketplace ratings and publisher verification. Review telemetry settings.
You can also check the trust score via API: GET /v1/preflight?target=GitHub.vscode-codeql
Key Safety Concerns for VS Code extensions
When evaluating any VS Code extension, watch for: code execution scope, telemetry, supply chain risk.
Trust Assessment
Github.Vscode Codeql has a Nerq Trust Score of 58/100 (C) and has not yet reached Nerq trust threshold (70+). This score is based on automated analysis of security, maintenance, community, and quality signals.
Key Takeaways
- Github.Vscode Codeql has a Trust Score of 58/100 (C).
- Review carefully before use — below trust threshold.
- Always verify independently using the Nerq API.
Frequently Asked Questions
Is Github.Vscode Codeql safe?
What is Github.Vscode Codeql's trust score?
What are safer alternatives to Github.Vscode Codeql?
Does Github.Vscode Codeql collect telemetry?
Is Github.Vscode Codeql's publisher verified?
Disclaimer: Nerq trust scores are automated assessments based on publicly available signals. They are not endorsements or guarantees. Always conduct your own due diligence.