JetBrains Marketplace Verified

RevenueCat Dashboard

by revenuecat · 653 users · 4.4 rating
001183ce-e3d3-5eb3-9d90-c4f27b0807bd | v1.2.7
21/ 100
LOW risk
No change since v1.2.6
Analyst verdict
No high-risk signal observed

Based on the RiskyPlugins AI security review of the observed evidence.

Analysis record

Analysed
Yesterday
Version
v1.2.7
Artifact
SHA256 AD2…EA9
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

48 detail rows
Showing 25 of 48 · highest severity first

Publisher Evidence

Low

revenuecat

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

72
Noisy-finding weight
x1.00
Publisher domain
revenuecat.com
Observed
Store verification signal
Verified publisher
Verified
Extension portfolio
2
Portfolio

12 evidence rows available.

Finding Categories

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality strong.

Filesystem/Process Access Justification

The RevenueCat Dashboard extension from RevenueCat is a JetBrains IDE plugin. The evidence shows 12 bundled JAR files in revenuecat-plugin/lib/ including kotlin-stdlib-jdk7-1.9.24.jar, kotlin-stdlib-jdk8-1.9.24.jar, ui-desktop-1.7.3.jar, and okio-jvm-3.9.1.jar. These are standard Kotlin/JVM runtime and UI libraries required for the extension to function. JetBrains plugins legitimately bundle dependencies in a lib/ directory, and these JAR files provide the necessary runtime environment for the plugin code. There are no findings indicating arbitrary filesystem access, process spawning, or workspace file reads beyond what a JetBrains plugin requires for its stated purpose.

Credential Access Findings

The findings summary shows "secret":"0" — there are zero credential access findings. No findings target .env files, .git/config, SSH keys, cloud credentials, or VS Code/JetBrains secret storage. The metadata findings in files like revenuecat-plugin/lib/annotation-jvm-1.8.0.jar and revenuecat-plugin/lib/markdown-jvm-0.7.3.jar are hash metadata, not credential-related code patterns. RevenueCat is a legitimate subscription management company, and this extension provides dashboard functionality within JetBrains IDEs, which does not require accessing developer credentials.

Strongest Counterargument

The strongest counterargument is the 96 high-severity malware-signature findings. However, examination of the actual finding content reveals these are metadata hash entries (e.g., HASH-80e07e4ca739f7b6, HASH-474e6bd2a6ac2362) from bundled JAR files, not actual malware signature detections. The findings_summary confirms "malware":"0" — zero actual malware findings. The malware-signature category here captures metadata hashes from bundled dependencies, which is a known false-positive pattern when scanning JAR files. Additionally, "network":"0", "obfuscation":"0", "code-smell":"0", and "tool-poisoning":"0" confirm no behavioral indicators of malicious activity. The extension has 353 users on JetBrains, and RevenueCat is a verified publisher. This is a bundled dependency false positive scenario where the scanning system flags JAR metadata as malware-signature findings without actual malicious content.

Key Reasons

  • 96 malware-signature findings are metadata hashes from bundled JARs, not actual malware
  • Zero credential access findings (secret: 0)
  • Zero network findings (network: 0)
  • Zero actual malware findings (malware: 0)
  • RevenueCat is a verified publisher on JetBrains marketplace

False Positive Considerations

  • Bundled JAR dependencies in lib/ directory
  • Metadata hash findings misclassified as malware-signature
  • Kotlin/JVM standard library files triggering false positives
  • No actual malware, network, or credential findings

Reviewed 2026-04-27; recommended action: suppress false positive; model confidence 85%.

JetBrains version history

Risk trend by version

4 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
21
Change since first
No change
Change from previous
No change
Versions:
First analyzed version
1.2.3
Apr 5, 2026
Risk range
21 to 21
Across analyzed versions
Latest analyzed version
1.2.7
Jun 2, 2026
Selected version
low
Version
v1.2.7
4 months ago
Risk score
21
Findings
48
Change vs previous
No change

Pick any point on the chart to explore that version's code below.

About This Extension

RevenueCat Dashboard integration for IntelliJ IDEA and Android Studio. Features: Connect to your RevenueCat Dashboard directly from your IDE Receive real-time...

Frequently Asked Questions