Is "Zero Git Deploy Toolkit" on JetBrains Marketplace Safe to Install?

zhaoxunyong · jetbrains · v1.0.11

A Zero Git Deploy Toolkit for Intellij IDEA, which can help us deploy git project more convenient. Before we released git branch manually, but made some mistakes...

Risk Assessment

Analyzed
73.01
out of 100
HIGH

7 security findings detected across all analyzers

JetBrains plugin analyzed via plugin.xml configuration and static code analysis

Severity Breakdown

0
Critical
2
High
2
Medium
0
Low
0
Info

Finding Categories

2
Malware Signatures
2
IoC Indicators

YARA Rules Matched

1 rule(2 hits)
postinstall system command

About This Extension

A Zero Git Deploy Toolkit for Intellij IDEA, which can help us deploy git project more convenient. Before we released git branch manually, but made some mistakes...

Detailed Findings

5 total

YARA Rule Matches

1 rule

Indicators of Compromise

Network indicators, suspicious strings, and potential IoCs extracted during analysis

Domains
2
Strings
2

All Indicators · 2

Domain
detected Domain: dz.tj

XIOC detected Domain: dz.tj

extracted_from_files

Domain
detected Domain: ĵ.bn

XIOC detected Domain: ĵ.bn

extracted_from_files

Security Analysis Summary

Security Analysis Overview

Zero Git Deploy Toolkit is a jetbrains extension published by zhaoxunyong. Version 1.0.11 has been analyzed by the Risky Plugins security platform, receiving a risk score of 73.01/100 (HIGH risk) based on 7 security findings.

Risk Assessment

This extension presents high security risk. Significant concerns were identified during analysis. It is not recommended for use in sensitive or production environments without thorough review.

Findings Breakdown

  • High: 2 finding(s)
  • Medium: 2 finding(s)

What Was Analyzed

The security assessment covers multiple analysis categories:

  • Malware Detection: YARA rule matching against 2,400+ malware signatures
  • Secret Detection: Scanning for exposed API keys, tokens, and credentials
  • Static Analysis: Code-level security analysis for common vulnerability patterns
  • Network Analysis: Detection of suspicious network communications and endpoints
  • Obfuscation Detection: Identification of code obfuscation techniques

Developer Information

Zero Git Deploy Toolkit is published by zhaoxunyong on the jetbrains marketplace. The extension has approximately 1K users.

Recommendation

This extension is not recommended for installation without thorough manual review. Consider alternatives with lower risk scores, or contact the developer to address the identified security concerns.

Frequently Asked Questions