For VS Code, Cursor and VSCodium

Secure SFTP & FTP upload on save that keeps working.

Wharfsync is the maintained successor for people who used the liximomo and Natizyskunk SFTP extensions. It reads your existing sftp.json, moves your passwords into your operating system keychain, and can never upload its own config to your server.

Wharfsync works on VS Code 1.124+ (where the old extension crashes with “isDate is not a function”), and on Cursor and VSCodium through Open VSX.

Why switch

Three problems the old extensions never fixed

It stopped working

The SFTP fork broke on VS Code 1.124 in June 2026 with TypeError: isDate is not a function. Wharfsync is built on current libraries and checked on every build for the Node APIs that caused it.

Passwords sat in a file

Plain-text passwords in sftp.json end up in git, in screenshots and on the server. Wharfsync keeps them in your OS keychain and warns you if a repository could expose them.

The config got uploaded

Upload-on-save could push sftp.json, password and all, into the web root. In Wharfsync, .vscode/ is never uploaded. That is a hard rule, not a setting.

Migrating from the SFTP extension

Keep your sftp.json. Switch in a minute.

  1. Install Wharfsync and disable the old SFTP extension (Wharfsync offers to, so files are not uploaded twice).
  2. Open your project. Wharfsync reads .vscode/sftp.json: hosts, ports, contexts, profiles, ignore lists.
  3. Review the diff that moves passwords into your keychain, then approve it. Upload on save carries on as before.

Features

Free does the job. Pro protects production.

FeatureFreePro
Reads your existing .vscode/sftp.json (liximomo / Natizyskunk format)✓ included✓ included
One-click import that moves passwords into your OS keychain (shows the diff first)✓ included✓ included
Upload on save, upload / download files and folders, status bar✓ included✓ included
Config and .vscode/ can never be uploaded (hard-coded)✓ included✓ included
Host keys pinned on first use; FTPS certificates pinned; plain-FTP warning✓ included✓ included
Asks before overwriting a newer server file, and before every delete✓ included✓ included
SSH agent and private keys with passphrases✓ included✓ included
Output log that removes secrets✓ included✓ included
Unlimited profiles and dev / staging / prod environments— not included✓ included
Colour-coded status bar and “you are about to deploy to PROD” check— not included✓ included
Remote explorer: browse, open, edit and save back, rename, delete— not included✓ included
Diff local against remote; sync preview (dry run) before applying— not included✓ included
Two-way folder sync by size + time or checksum— not included✓ included
Watch mode for build output folders— not included✓ included
Jump hosts (ProxyJump) and parallel transfers— not included✓ included
Automatic local backup of every file before it is overwritten (7 days)— not included✓ included

Pricing

Simple pricing in pounds

The price shown is the total you pay. No trial; cancel whenever you like and Pro runs to the end of the period you paid for.

Free

£0

For one server profile

  • Everything in the Free column
  • Secure by default
Install free

Questions

Before you install

Does Wharfsync send my files or passwords anywhere?

Only to the servers in your sftp.json. There is no telemetry. The only thing that ever reaches us is your licence key, once a day, if you subscribe. See the Privacy Notice and the security model.

Does Pro work offline?

Yes. Licence keys are signed and checked on your computer. A key keeps working until the end of your paid period plus 7 days even if it cannot reach us.

Which protocols?

SFTP (password, private key with passphrase, or SSH agent), FTP and FTPS (explicit and implicit). Pro adds jump hosts.

How do I cancel?

From the Manage page or the “Wharfsync: Manage or cancel subscription” command, in the Stripe customer portal. See the Refund & Cancellation Policy.