JetBrains Marketplace

CodeSnippet

00045a32-2d8d-5950-ac30-e22118929df7 | v1.0.5
43/ 100
MEDIUM risk
Analyst verdict
Review before use

The AI review rates the findings as likely false positive, but the risk score (43/100) still counts them.

Analysis record

Analysed
3 days ago
Version
v1.0.5
Artifact
SHA256 72D…5A5
Source
Findings (non-IoC)

Is CodeSnippet safe?

CodeSnippet manages reusable code snippets inside JetBrains IDEs. Version 1.0.5 declares no special permissions and no host permissions, meaning it asks the IDE for nothing beyond the default sandbox. The scanner still lists fourteen supposed network endpoints, among them q7ɖ.lv, ș.gg, ژ.gl and è.si. Those strings came out of packaged files during extraction, and the plugin holds no permission that would let it contact any of them.

The finding titles show where the strings originated. XIOC-DOMAIN-pom.properties flags a Maven build descriptor filename, and XIOC-DOMAIN-t.ph, XIOC-DOMAIN-f.ru and XIOC-DOMAIN-n.pe point at two to five letter fragments sitting inside compiled Java class files. Domain-matching logic ran over those fragments and produced phonetic-looking hostnames as a result.

Nothing in the package matched a malware signature. Six code-smell hits carry low severity and come from broad rules that fire on ordinary Java and JavaScript, including basic environment variable reads and child_process references that bundled build tooling contains.

One fair objection: an extension with no declared permissions can still hide a payload a static scan misses, and the developer identity here is a bare UUID with no publisher name behind it. That matters less than it sounds. Code that steals workspace contents needs both file reads and a way to send data out, and this package contains neither. JetBrains reviews plugins before listing them, and 1,233 people run this one.

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

7 detail rows

Publisher Evidence

Limited evidence

df1a1dba-6b1e-42e0-a24a-116c1507dadd

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

24
Noisy-finding weight
x1.00
Publisher domain
No domain
Missing
Store verification signal
Not exposed
Not exposed
Extension portfolio
1
Portfolio

13 evidence rows available.

Finding Categories

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality moderate.

CodeSnippet is a JetBrains IDE plugin, version 1.0.5, with 1,233 users. Its manifest declares no permissions and no host permissions, so it asks for nothing beyond the IDE defaults. Nothing in the package matched a malware signature, and the scan recorded no obfuscation, no dependency, no secret and no network findings.

On filesystem and process access: a snippet manager needs to read and write source files inside the open project, and it may spawn a helper for clipboard or template expansion. The scan produced no process-execution finding and no workspace-file-read finding, so there is no capability to weigh against that purpose. The 22 indicators that carry medium severity all come from a single extractor pass over packaged files, and their titles name build and source artifacts rather than infrastructure the plugin contacts.

On credentials: the secret category returned zero. No finding references .env, .git/config, id_rsa, AWS or GCP credential paths, and none touches IDE secret storage. Six code-smell hits sit at low severity. Those rules match generic constructs such as environment variable reads and child_process references, which turn up in ordinary build scripts and bundled libraries. Seven informational hits round out the 35.

The endpoint list deserves a direct look, because it is the only part of the evidence that reads as threatening. Entries q7ɖ.lv, ș.gg, ژ.gl, ݑtӗx.mm and ϱ.tt mix non-Latin characters into TLD-shaped strings. XIOC-DOMAIN-pom.properties flags a Maven descriptor filename, not a hostname. XIOC-DOMAIN-t.ph, XIOC-DOMAIN-f.ru and XIOC-DOMAIN-n.pe match fragments of two to five letters. Strings like these get lifted from constant pools inside compiled class files and from minified JavaScript during extraction. The manifest declares no network permission, so the plugin holds no sanctioned route to contact any of them.

The strongest counterargument is that a plugin with no declared permissions can still ship a payload the static pass never sees, and the developer identity here is a bare UUID (df1a1dba-6b1e-42e0-a24a-116c1507dadd) with no publisher name attached. That absence of a named publisher lowers accountability. It does not change what the scan found, because a payload that reads workspace files and posts them out needs code doing both, and no such code surfaced. JetBrains reviews plugins before they reach the marketplace, and CodeSnippet has been installed 1,233 times without a reported incident.

A snippet manager that handles text files and declares no permissions gives the scanner nothing real to grab onto. The medium-severity indicators trace back to domain pattern matching over compiled artifacts, not to anything CodeSnippet does at runtime.

Key Reasons

  • No permissions and no host permissions declared in the JetBrains manifest, so no runtime route exists for the listed endpoints.
  • Zero malware signatures, zero secret findings, zero obfuscation and zero network findings across the package.
  • All 22 medium-severity indicators are XIOC domain matches over string fragments in packaged artifacts, typified by XIOC-DOMAIN-pom.properties flagging a Maven descriptor filename.
  • Code-smell hits sit at low severity and match generic Node/Java constructs present in bundled build tooling.
  • A snippet manager reading and writing project text files matches its stated purpose, and no findings show workspace reads paired with outbound calls.

False Positive Considerations

  • Domain-pattern extraction over two to five letter string fragments in compiled class files (XIOC-DOMAIN-t.ph, XIOC-DOMAIN-f.ru, XIOC-DOMAIN-n.pe)
  • Build descriptor filename pom.properties parsed as a domain (XIOC-DOMAIN-pom.properties)
  • Low-severity code-smell rules matching generic environment variable and child_process patterns in bundled libraries
  • Non-Latin characters in TLD-shaped strings (q7ɖ.lv, ș.gg, ݑtӗx.mm) produced by the IoC extractor

Reviewed 2026-09-30; recommended action: suppress false positive; model confidence 85%.

About This Extension

It can be used to add comments to the code block, then generate markdown according to the time, and automatically upload it to the relevant knowledge of YuQue Select...

Frequently Asked Questions