Catch security issues
before you commit.
The Scanverra extension scans your open workspace for secrets, SAST issues, dependency CVEs, IaC misconfigurations and quality issues, and shows each finding right on the line it belongs to.
Works in VS Code 1.85 or newer. Requires a Pro, Team or Enterprise plan.
Scanverra: Scan Results
Quality gate failed
184 files · 14 findings
Scanned just now
Hardcoded AWS access key
scanverra(secrets/aws-access-key)
Security review, inside your editor
The same checks as the dashboard and the CLI, right next to your code.
Findings on the exact line
Every finding becomes a squiggle in the editor and an entry in the Problems panel, so you fix it where it lives instead of hunting through a report.
A sidebar built for triage
Score, quality gate, severity filters and search, findings grouped by file, plus dependency CVEs with the version to upgrade to. Click any finding to jump to it.
Log in without leaving VS Code
Paste an API key into the sidebar and you are set. Already use the CLI? The extension picks up the same login automatically.
Your code stays on your machine
The signed rules are downloaded and verified, then every file is scanned locally. The extension never uploads your code or a report.
How it works
From install to your first finding in about a minute.
Install
Search for Scanverra in the Extensions view, or install it from the Visual Studio Marketplace.
Log in
Open the Scanverra view in the Activity Bar and paste an API key from your dashboard.
Scan
Click Scan Workspace. The checks run locally and the score appears in the sidebar and status bar.
Fix
Open a finding, read the suggested fix, and re-scan to watch the score go up.
What you get
Everything the Scanverra engine checks, surfaced where you write code.
Related reading
Automating Code Quality and Dependency Audits in CI/CD
How to catch vulnerable dependencies, license issues, and quality drift on every pull request instead of during a quarterly cleanup.
npm audit vs. Snyk vs. Dependabot: Choosing the Right Dependency Scanner
Three names that come up constantly, doing genuinely different jobs - and why most teams end up using more than one, not choosing just one.
Understanding CVSS Scores: How to Prioritize Vulnerability Fixes
A 9.8 and a 7.5 aren't just "high" and "medium" - what actually goes into a CVSS score, and why the number alone shouldn't decide what you patch first.
Scanverra CLI
Run the same scan in your terminal or CI
Repo Scanner
Code quality & dependency health
Security Scanner
Headers, secrets, SSL & CSRF risk
Website Audit
Performance, SEO & accessibility
Bring Scanverra into your editor
Install the extension, paste your API key, and see your first findings in under a minute.