Real-time security vulnerability detection for VS Code and Cursor. Catches hardcoded secrets, injection risks, insecure crypto, and unsafe patterns as you code.
Installation
Launch VS Code Quick Open (Ctrl+P), paste the following command, and press enter.
Real-time security vulnerability detection for VS Code and Cursor. Catch hardcoded secrets, injection risks, insecure crypto, and unsafe patterns as you code.
Features
Real-time scanning — Automatically analyzes files on save and open
10 built-in rules — Covers OWASP Top 10 and common vulnerability patterns
CWE references — Each finding links to its CWE entry for full context
Workspace scan — Scan your entire project in one command
Configurable — Enable/disable individual rules, set severity, exclude paths
Zero dependencies — Runs entirely in VS Code, no external services needed
Getting Started
Install the extension
Open any code file — SecureLint scans automatically
Press ⌘⇧L (Mac) or Ctrl+Shift+L (Windows/Linux) to manually scan
Security Rules
Rule
Detects
Severity
CWE
hardcoded-secret
API keys, passwords, tokens in source code
Error
CWE-798
sql-injection
String concatenation in SQL queries
Error
CWE-89
xss-risk
innerHTML, eval(), document.write()
Error
CWE-79
insecure-http
Non-HTTPS URLs (excluding localhost)
Warning
CWE-319
weak-crypto
MD5, SHA1, DES, RC4 usage
Warning
CWE-327
path-traversal
File ops with unsanitized user input
Warning
CWE-22
command-injection
Shell commands with user input
Error
CWE-78
insecure-random
Math.random() for security purposes
Warning
CWE-338
debug-leak
Logging sensitive variables
Info
CWE-532
cors-wildcard
Permissive CORS (origin: *)
Warning
CWE-942
Commands
Command
Shortcut
Description
SecureLint: Scan Current File
⌘⇧L / Ctrl+Shift+L
Scan the active file
SecureLint: Scan Workspace
—
Scan all workspace files
SecureLint: Toggle Auto-Scan
—
Enable/disable real-time scanning
SecureLint: Show Security Rules
—
Browse all security rules
Configuration
Setting
Default
Description
securelint.autoScan
true
Auto-scan on save/open
securelint.severity
"warning"
Default severity level
securelint.enabledRules
All rules
Which rules to apply
securelint.excludePatterns
node_modules, .git, dist, build
Glob patterns to skip
securelint.maxFileSize
500000
Max file size to scan (bytes)
Status Bar
The SecureLint ✓ / SecureLint ⚠ N status bar item shows the current file's security status. Click it to toggle auto-scan.
Supported Languages
Works with all text files. Language-specific rules (SQL injection, XSS, command injection) target:
JavaScript, TypeScript, Python, Java, PHP, Ruby, React (JSX/TSX)