Skip to content
| Marketplace
Sign in
Visual Studio Code>Linters>QuantumGuard - Post-Quantum Crypto Security AnalyzerNew to Visual Studio Code? Get it now.
QuantumGuard - Post-Quantum Crypto Security Analyzer

QuantumGuard - Post-Quantum Crypto Security Analyzer

Quantum Guard

| (0) | Free
Detects quantum-vulnerable cryptography and other crypto security issues (RSA, ECDSA, MD5, SHA-1, weak RNG, hardcoded keys) with real-time warnings, hover details, project-wide scanning, and readiness reports.
Installation
Launch VS Code Quick Open (Ctrl+P), paste the following command, and press enter.
Copied to clipboard
More Info

QuantumGuard — Post-Quantum Crypto Security Analyzer

A VS Code extension that statically analyzes Python, Java, JavaScript, and TypeScript code for:

  • Quantum-vulnerable algorithms — RSA, ECDSA, DSA (broken by Shor's algorithm on a sufficiently capable quantum computer), with migration guidance to ML-KEM / ML-DSA (NIST FIPS 203 / 204).
  • Classically broken/weak crypto — MD5, SHA-1, AES in ECB mode.
  • Weak configuration — RSA keys under 2048 bits.
  • Insecure randomness — random/Math.random()/java.util.Random used in security-relevant contexts.
  • Possible hardcoded secrets — heuristic match on variable names + secret-shaped string literals.

Features

  1. Real-time detection — warnings appear as you type, using VS Code's Diagnostics API (same mechanism as the built-in linter squiggles).
  2. Hover details — hover over a flagged line for threat explanation + recommended fix.
  3. Project scan — QuantumGuard: Scan Project for Crypto Issues walks every supported file in the workspace and summarizes findings.
  4. Quantum Readiness Report — QuantumGuard: Generate Quantum Readiness Report opens a styled report webview grouped by severity.

Project Structure

quantumguard/
├── package.json          # Extension manifest (commands, config, activation events)
├── tsconfig.json
├── src/
│   ├── extension.ts       # Entry point — wires everything together
│   ├── rules.ts            # All detection rules (data-driven — add new checks here)
│   ├── scanner.ts          # Core text-scanning engine (shared by all features)
│   ├── diagnostics.ts      # Real-time warning squiggles
│   ├── hoverProvider.ts    # Hover popups
│   ├── scanCommand.ts      # Project-wide scan command
│   └── reportGenerator.ts  # Webview report
├── sample-test-files/
│   └── vulnerable_example.py   # Test file with one of every issue type
└── .vscode/
    ├── launch.json         # F5 debug config
    └── tasks.json          # Auto-compile before debug launch

Setup & Run Locally

Prerequisites: Node.js 18+ and VS Code installed.

  1. Install dependencies

    cd quantumguard
    npm install
    
  2. Compile TypeScript

    npm run compile
    

    (Or run npm run watch in a terminal to auto-recompile on save while you work.)

  3. Open the folder in VS Code

    code .
    
  4. Launch the Extension Development Host Press F5 (or Run → Start Debugging). This opens a second VS Code window with QuantumGuard active.

  5. Test it In the new window, open sample-test-files/vulnerable_example.py. You should immediately see warning squiggles under the RSA, MD5, SHA-1, random.random(), and hardcoded-key lines.

    • Hover over any flagged line to see the detail popup.
    • Open the Command Palette (Cmd/Ctrl+Shift+P) and run QuantumGuard: Scan Project for Crypto Issues to scan every file in the workspace.
    • Run QuantumGuard: Generate Quantum Readiness Report to see the full report view.

Packaging as a real, installable .vsix

Once you're happy with it, you can package this into a real, installable extension file:

npm install -g @vscode/vsce
vsce package

This produces a quantumguard-0.1.0.vsix file. Install it into any VS Code with:

code --install-extension quantumguard-0.1.0.vsix

Known Limitations (worth stating honestly — e.g. in an interview or resume writeup)

  • Detection is regex/line-based, not AST-based. This keeps it fast and simple to extend, but it can produce false positives (e.g., hashlib.md5(data, usedforsecurity=False) is flagged even though Python 3.9+ has a way to mark that hash as non-security use). A natural v2 improvement is parsing a real AST per language for higher precision.
  • Hardcoded secret detection and weak-RNG detection are heuristic and will have a higher false-positive rate than the algorithm-name checks — they're included because they're genuinely useful, but should be tuned against real codebases.
  • Comment-line filtering is basic (skips lines starting with #, //, *) and won't catch multi-line comments or inline trailing comments perfectly.

Extending the Rule Set

All detection logic lives in src/rules.ts as data — to add a new check, add a new object to the RULES array with a pattern (regex), severity, and messaging. No other file needs to change.

  • Contact us
  • Jobs
  • Privacy
  • Manage cookies
  • Terms of use
  • Trademarks
© 2026 Microsoft