Open VSX and vsce preflight for extension authors: flags SVG icons, http or untrusted SVG badges, missing publisher/engines, Microsoft-only dependencies and VSCE_PAT publishing before 2026-12-01. Runs entirely in your browser — nothing is uploaded.
Full version: whole-workspace publish plan, dated migration report and CI gate - $29 once, one licence key per person or team seat.
Same engine as the VS Code extension, byte for byte.
Whole-workspace publish plan: every extension manifest and workflow in the repo, a dated migration report, and a CI gate that fails a build adding a new blocker.
One payment, one licence key for this tool. The key is shown right after payment.
US software developer median wage: $65.38 an hour (BLS OEWS, occupation 15-1252, 2025 data)
Buy the full version — $29· ReadyStack
Real numbers from this tool, line by line.

Six release errors in one sample package.json: that is what Open VSX Publish Gate reports for a VS Code extension author who publishes to the Visual Studio Marketplace and wants the same build on Open VSX, where VSCodium, Cursor, Windsurf and Gitpod users install from.
The official vsce publishing page now carries this line: "On December 1, 2026, global Personal Access Tokens (PATs) in Azure DevOps are retired." The same page still tells you to create the publishing PAT with Organization set to All accessible organizations. That is a global PAT. If your release job runs vsce publish -p $VSCE_PAT, it stops working on December 1, 2026. The replacement is vsce publish --azure-credential, which signs in with Microsoft Entra ID.
Many teams use that deadline to move the release job anyway, and add Open VSX in the same pull request. That is where the second set of problems shows up.
The sample is an extension called py-lens. The gate reads the file once and reports 10 findings: 6 errors, 3 warnings and 1 info.
The 6 errors:
The 3 warnings: the publish script passes $VSCE_PAT, nothing runs ovsx publish, and there is no repository field. The info finding is the missing license field.
vsce package throws on the first error it meets. Six errors means six rounds of fix, re-run, read the next error. And vsce never checks Open VSX at all: a Pylance dependency packages without a word, then breaks installs in VSCodium. The gate prints every finding with its line and the replacement line in one pass, from 16 rules.
The gate also reads the workflow file. If it sees vsce publish or a Marketplace registryUrl with a VSCE_PAT secret, it flags the PAT. If nothing reaches open-vsx.org, it prints the ovsx step to add.
The free check covers the file you have open, in full, in VS Code or in the web version. Nothing is hidden. The full version adds the whole workspace: every extension manifest and workflow in the repo, a dated migration report, and a CI gate that fails a build adding a new blocker.
Sources: the vsce publishing page on code.visualstudio.com, the Open VSX publishing wiki, the vsce source (package.js), and open-vsx.org/api lookups made on 2026-09-30.
It reads a VS Code extension's package.json or its GitHub publish workflow and lists every line that stops vsce or ovsx: an SVG icon, http or untrusted SVG badges, a semver pre-release version, a missing publisher or engines field, Microsoft-only dependencies that return 404 on open-vsx.org, and a VSCE_PAT that global PAT retirement on December 1, 2026 will break. Each finding carries the replacement line.
VS Code extension authors and small tool teams who publish to the Visual Studio Marketplace and want the same release on Open VSX, where VSCodium, Cursor, Windsurf and Gitpod users install from. It also fits maintainers whose release job still runs vsce publish with a Personal Access Token and who have to switch to Microsoft Entra ID before December 1, 2026.
vsce throws on the first error it meets, so a manifest with 6 errors takes 6 rounds of fix and re-run. It never checks Open VSX: an extension that lists ms-python.vscode-pylance in extensionDependencies packages fine, yet VSCodium users cannot install it because that ID returns 404 on open-vsx.org. The gate lists all 16 rule hits in one pass.
Free, with no key: the open package.json or workflow file is checked in full and every finding shows its line and the fix; the web version does the same for a pasted file. The $29 key adds the whole workspace: every extension manifest and publish workflow in the repo, a dated migration report you can file, and a CI gate that fails a build adding a new blocker.
The free tier costs nothing and ends the job for one file. The full version is $29 once, one licence key per person or team seat, no subscription. The yardstick: a US software developer's median wage is $65.38 an hour (BLS OEWS 2025), and doing this by hand means reading the vsce trusted-host list and querying open-vsx.org per dependency ID.
One question, answered by the person who built it. Your email only if you want the answer sent.