Skip to content
| Marketplace
Sign in
Visual Studio Code>Programming Languages>Zcodee AI — Code analyst and vulnerability ScannerNew to Visual Studio Code? Get it now.
Zcodee AI — Code analyst and vulnerability Scanner

Zcodee AI — Code analyst and vulnerability Scanner

Sicily labs

|
66 installs
| (1) | Free
AI-powered vulnerability scanner that analyzes your entire codebase and delivers a prioritized, actionable security report with concrete fix suggestions.
Installation
Launch VS Code Quick Open (Ctrl+P), paste the following command, and press enter.
Copied to clipboard
More Info

Zcodee — AI Security Scanner for VS Code

AI-powered vulnerability scanner that analyzes your entire codebase and delivers a prioritized, actionable security report — directly inside VS Code.

Features

  • One-click scan — Click "Run Scan" in the sidebar to analyze your open workspace
  • AI-powered analysis — Deep multi-file vulnerability detection across 170+ CWE categories
  • Streaming thinking UX — Watch the AI reason through your code in real-time with a hacker-themed analysis feed
  • Inline results — Expand any finding to see the attack vector, impact, code snippet, and concrete fix suggestion
  • Click-to-open — Jump directly to the vulnerable line in your editor
  • Scan history — View all past scans and their risk scores
  • Incremental scanning — Unchanged files are cached, so rescans are 70–90% faster
  • Credit system — 5 free scans on signup, contact sales for more credits or a plan upgrade

Getting Started

  1. Install the extension from the Marketplace
  2. Click the Zcodee shield icon in the Activity Bar
  3. Click Sign in — you'll be taken to the web app to create an account
  4. Open a project folder and click Run Scan

Extension Settings

Setting Default Description
zcodee.apiUrl https://api.zcodee.com Backend API base URL
zcodee.webUrl https://zcodee.com Web app URL for sign-in

Supported Languages

Java, Kotlin, Python, JavaScript, TypeScript, Go, Ruby, PHP, C#, Rust, Swift, C/C++, Scala, Groovy — plus config files like Dockerfile, YAML, Terraform, and .env.

How It Works

  1. The extension collects source files from your workspace (up to 300 files, max 1 MB each)
  2. Files are sent to the Zcodee backend over TLS for analysis
  3. The backend runs Semgrep static analysis first, then AI deep analysis on flagged/high-priority files
  4. Results are streamed back with severity rankings, attack vectors, and fix suggestions
  5. Your source code is not retained after analysis — only findings and file fingerprints are stored

Requirements

  • A Zcodee account (free signup at zcodee.com)
  • VS Code 1.85.0 or later
  • Internet connection for backend communication

Pricing

Plan Price Includes
Free $0 5 scans on signup, max 50 files/scan
Pro Contact Sales Unlimited scans, no file limit, PDF reports
Team Contact Sales Shared credit pool, 5 seats, org management
Enterprise Contact Sales On-premise, SSO, custom AI, dedicated SLA

Pricing is handled manually — contact us and we'll get back to you within 1 business day.

Release Notes

1.0.0

  • Initial production release
  • Full real-time AI vulnerability analysis powered by Zcodee AI
  • Streaming thinking phases with hacker-themed UX (Reconnaissance → Threat Modeling → Static Analysis → Deep Reasoning → Report Generation)
  • Interactive findings with click-to-open file navigation
  • Scan history with risk scores and severity counts
  • Browser-based authentication via VS Code URI handler
  • Credit balance display in the top bar
  • Incremental scanning — unchanged files cached for 70–90% faster rescans
  • Default backend: https://api.zcodee.com

Links

  • Documentation
  • Dashboard
  • Report Issues

Built with ❤️ by Sicily Labs

  • Contact us
  • Jobs
  • Privacy
  • Manage cookies
  • Terms of use
  • Trademarks
© 2026 Microsoft