shouldiuse.io

Categories

VERDICT

Should I use Open-vsx?

Cookie settings - open-vsx.org

Depends. Use Open VSX if you run a non-Microsoft VS Code-compatible editor or want vendor-neutral extension publishing; it is free and Eclipse-backed. Skip it if you use standard VS Code — the official marketplace is the safer default, and malware has repeatedly slipped through Open VSX review.

Confidence

Medium. Based on 50+ public sources: official Eclipse pages, security research, CVE databases, news, and Reddit threads.

Ratings

  • Value for money
  • Ease of use
  • Feature depth
  • Support qualityNo support evidence in sources
  • Security posture

Pricing

Free

Open VSX Registry

ModelNot disclosed
Monthly fees300M
HardwareNot disclosed
Free tierYes
Managed Open VSXUsage-based (undisclosed)

Best for

  • Non-Microsoft VS Code-compatible editors
  • Extension publishers wanting vendor-neutral distribution
  • Enterprises needing a managed extension registry
  • Open-source toolchains avoiding Microsoft licensing

Not for

  • Microsoft VS Code users happy with the official marketplace
  • Buyers expecting curated, malware-safe extensions out of the box
  • Teams needing an SLA on the free tier — that is what Managed Open VSX costs for
  • Non-technical buyers — this is developer infrastructure, not a business app

Gotchas - check before you buy

high

Malicious extensions repeatedly passed review — vet publishers and versions before installing

medium

Managed Open VSX is usage-based pricing; costs can scale unpredictably

medium

Free registry is not built for critical workloads — that is the paid Managed tier's pitch

medium

Guess: not every VS Code Marketplace extension is published here

Pros and cons

Pros

  • Free, open-source, vendor-neutral extension registry
  • 300M monthly downloads — large ecosystem
  • Eclipse Foundation governance with AWS funding backing
  • Managed Open VSX offers production-grade hosting
  • Security researcher program and pre-publish checks now rolling out

Cons

  • Repeated malware: GlassWorm and 77 'evil twin' extensions removed
  • Multiple CVEs in the registry itself, 2025–2026
  • Pre-publish security checks only recently implemented
  • Community openly questions long-term sustainability

Sources & method

Analyzed 10/02/2026 - 12 sources - Frequent attack target: malware campaigns, compromised publisher accounts, and several CVEs since 2025; hardening is in progress.

official x4review x2security x3news x3
  • GlassWorm loader via suspected developer account compromise, Threat actors compromised developer accounts to push the GlassWorm loader to Open VSX.
  • 77 malicious 'evil twin' extensions harvesting developer data, Counterfeit extensions impersonated legitimate tools; removed after a July–August 2026 campaign.
  • CVE-2026-13323, Vulnerability in Open VSX tracked in NVD, July 2026.
  • CSRF and SSRF vulnerabilities, CVE-2026-90882 (CSRF) and CVE-2025-12999 (SSRF) in the Open VSX Registry.

Key stats

  • Value for money: 5/5

    Rating

  • Free

    Starting price

  • 12

    Sources

  • Analyzed

  • Value for money: 5/5. Registry itself is free
  • Ease of use: 4/5. Switchers report drop-in marketplace replacement
  • Feature depth: 3/5. Hit 1.0.0 only in 2026
  • Support quality. No support evidence in sources
  • Security posture: 2/5. Malware waves and CVEs; hardening underway
  • 300M Monthly downloads as of March 2026
  • Free Registry price Eclipse open-source project
  • 77 Malicious extensions removed 'Evil twin' wave, Aug 2026
  • 4+ Named CVEs in registry 2025–2026, incl. CSRF and SSRF

Pricing

Open VSX Registry

Free

  • Publish and install extensions free
  • Eclipse Foundation-run community service

Managed Open VSX

Usage-based (undisclosed)

  • Production-grade hosted registry
  • For orgs where Open VSX is critical

Security

Frequent attack target: malware campaigns, compromised publisher accounts, and several CVEs since 2025; hardening is in progress.

  • GlassWorm loader via suspected developer account compromiseThreat actors compromised developer accounts to push the GlassWorm loader to Open VSX.⁷
  • 77 malicious 'evil twin' extensions harvesting developer dataCounterfeit extensions impersonated legitimate tools; removed after a July–August 2026 campaign.⁶
  • CVE-2026-13323Vulnerability in Open VSX tracked in NVD, July 2026.⁸
  • CSRF and SSRF vulnerabilitiesCVE-2026-90882 (CSRF) and CVE-2025-12999 (SSRF) in the Open VSX Registry.

Alternatives

Compare Open-vsx with each alternative.

  • Visual Studio Code Marketplace

    Microsoft's default; biggest catalog if you use VS Code.

  • Self-hosted Open VSX

    Same open-source software, run it yourself for control.

Companies that use it

  • Google (Anti-Gravity editor)
  • Cline
  • Qodo (Codium)
  • GrapeCity

Companies that could

  • Microsoft11 Uses Visual Studio Code Marketplace instead
Full analysis

Based on 50+ public sources: official Eclipse pages, security research, CVE databases, news, and Reddit threads.

Free open extension registry for VS Code-like editors. Good for vendor neutrality; recent malware waves mean vet everything.

Methodology

Based on 50+ public sources: official Eclipse pages, security research, CVE databases, news, and Reddit threads.

Sources

  1. official
  2. Open VSX Registryopen-vsx.org
    official
  3. official
  4. Managed Open VSX pricingmanaged.open-vsx.org
    official
  5. news
  6. security
  7. security
  8. security
  9. news
  10. news
  11. review
  12. review

Rate this review

Anonymous. You can change your vote.

Loading votes…

Comments

One queue. No nested comments. Give a display name first. Limit: 200 words per comment and 7 comments per day. You can edit or delete yours.

Save a name to write a comment.

0 / 200 words

No comments yet.