RevenueCat Dashboard
Based on the RiskyPlugins AI security review of the observed evidence.
Analysis record
- Analysed
- Yesterday
- Version
- v1.2.7
- Artifact
- SHA256 AD2…EA9
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
Publisher Evidence
Lowrevenuecat
Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
12 evidence rows available.
Finding Categories
AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality strong.
Filesystem/Process Access Justification
The RevenueCat Dashboard extension from RevenueCat is a JetBrains IDE plugin. The evidence shows 12 bundled JAR files in revenuecat-plugin/lib/ including kotlin-stdlib-jdk7-1.9.24.jar, kotlin-stdlib-jdk8-1.9.24.jar, ui-desktop-1.7.3.jar, and okio-jvm-3.9.1.jar. These are standard Kotlin/JVM runtime and UI libraries required for the extension to function. JetBrains plugins legitimately bundle dependencies in a lib/ directory, and these JAR files provide the necessary runtime environment for the plugin code. There are no findings indicating arbitrary filesystem access, process spawning, or workspace file reads beyond what a JetBrains plugin requires for its stated purpose.
Credential Access Findings
The findings summary shows "secret":"0" — there are zero credential access findings. No findings target .env files, .git/config, SSH keys, cloud credentials, or VS Code/JetBrains secret storage. The metadata findings in files like revenuecat-plugin/lib/annotation-jvm-1.8.0.jar and revenuecat-plugin/lib/markdown-jvm-0.7.3.jar are hash metadata, not credential-related code patterns. RevenueCat is a legitimate subscription management company, and this extension provides dashboard functionality within JetBrains IDEs, which does not require accessing developer credentials.
Strongest Counterargument
The strongest counterargument is the 96 high-severity malware-signature findings. However, examination of the actual finding content reveals these are metadata hash entries (e.g., HASH-80e07e4ca739f7b6, HASH-474e6bd2a6ac2362) from bundled JAR files, not actual malware signature detections. The findings_summary confirms "malware":"0" — zero actual malware findings. The malware-signature category here captures metadata hashes from bundled dependencies, which is a known false-positive pattern when scanning JAR files. Additionally, "network":"0", "obfuscation":"0", "code-smell":"0", and "tool-poisoning":"0" confirm no behavioral indicators of malicious activity. The extension has 353 users on JetBrains, and RevenueCat is a verified publisher. This is a bundled dependency false positive scenario where the scanning system flags JAR metadata as malware-signature findings without actual malicious content.
Key Reasons
- 96 malware-signature findings are metadata hashes from bundled JARs, not actual malware
- Zero credential access findings (secret: 0)
- Zero network findings (network: 0)
- Zero actual malware findings (malware: 0)
- RevenueCat is a verified publisher on JetBrains marketplace
False Positive Considerations
- Bundled JAR dependencies in lib/ directory
- Metadata hash findings misclassified as malware-signature
- Kotlin/JVM standard library files triggering false positives
- No actual malware, network, or credential findings
Reviewed 2026-04-27; recommended action: suppress false positive; model confidence 85%.
JetBrains version history
Risk trend by version
4 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace