Is "Jujutsu Kaizen" on OpenVSX Registry Safe to Install?

Verified
jjk · openvsx · v0.9.3

Jujutsu (jj) version control system for VS Code

Risk Assessment

Analyzed
31.18
out of 100
LOW

9 security findings detected across all analyzers

Open VSX extension analyzed via package manifest and static code analysis

Severity Breakdown

0
Critical
0
High
0
Medium
9
Low
0
Info

Finding Categories

About This Extension

Jujutsu (jj) version control system for VS Code

Detailed Findings

9 total

Security Analysis Summary

Security Analysis Overview

Jujutsu Kaizen is a OpenVSX Registry extension published by jjk. Version 0.9.3 has been analyzed by the Risky Plugins security platform, receiving a risk score of 31.18/100 (LOW risk) based on 9 security findings.

Risk Assessment

This extension presents low security risk. Some minor findings were detected, but nothing that would prevent typical usage. Reviewing the detailed findings below is recommended before use in sensitive environments.

Findings Breakdown

  • Low: 9 finding(s)

What Was Analyzed

The security assessment covers multiple analysis categories:

  • Malware Detection: YARA rule matching against 2,400+ malware signatures
  • Secret Detection: Scanning for exposed API keys, tokens, and credentials
  • Static Analysis: Code-level security analysis for common vulnerability patterns
  • Network Analysis: Detection of suspicious network communications and endpoints
  • Obfuscation Detection: Identification of code obfuscation techniques

Developer Information

Jujutsu Kaizen is published by jjk on the OpenVSX Registry marketplace.

Recommendation

Exercise caution with this extension. Review the detailed findings and ensure the requested permissions align with the extension's stated functionality before installation.

Frequently Asked Questions