JetBrains Marketplace Verified

ZenStack Language Tools

by ZenStack · 3.7K users · 2.2 rating
3f076e92-3e89-573c-b165-797b824ef25f | v2.20.0
73/ 100
HIGH risk
Analyst verdict
Review before use

The AI review rates the findings as likely false positive, but the risk score (73/100) still counts them.

Analysis record

Analysed
3 days ago
Version
v2.20.0
Artifact
SHA256 26B…A29
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

10 detail rows

YARA Rule Matches

1 rule
SeverityRuleHitsFilesMetadata
HIGHsupply chain sourcemap appended iife 1
zenstack/language-server/main.js
-

Publisher Evidence

Limited evidence

ZenStack

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

32
Noisy-finding weight
x1.00
Publisher domain
whimslab.io
Observed
Store verification signal
Not exposed
Not exposed
Extension portfolio
1
Portfolio

13 evidence rows available.

Finding Categories

1
Malware Signatures
3
Obfuscation

YARA Rules Matched

1 rule
supply chain sourcemap appended iife

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality strong.

ZenStack Language Tools is a JetBrains IDE extension that provides language server support and syntax highlighting for ZenStack, a data modeling and ORM framework. The extension's filesystem and process access is fully justified by its stated purpose as a language tool. The extension contains legitimate development files including zenstack/language-server/main.js for language server functionality, zenstack/res/zmodel.tmbundle/Syntaxes/zmodel.tmLanguage for syntax highlighting, and bundled JAR files like zenstack/lib/searchableOptions-2.20.0.jar and zenstack/lib/instrumented-zenstack-2.20.0.jar for runtime libraries.

There are no credential-access findings targeting actual secrets. The findings summary shows zero detections in the "secret" category, meaning no code was flagged for reading .env files, SSH keys, cloud credentials, or VS Code secret storage. The extension's metadata findings consist entirely of file integrity hashes for its own bundled resources, which is standard practice for extension integrity verification and poses no security risk.

The strongest counterargument to this verdict would be that any extension with language server capabilities inherently has broad filesystem access and could theoretically exfiltrate code. However, this argument does not apply here because the findings show zero network activity flags, zero data exfiltration patterns, and zero malware signatures. The threat_indicators summary explicitly shows "ioc":"0","malware-signature":"0","malware":"0","network":"0", confirming no suspicious behavior was detected. Additionally, the extension has 3,599 users on JetBrains Marketplace, indicating it is actively maintained and widely trusted in the developer community.

All six findings in the bundle are "info" severity metadata entries containing SHA hashes of the extension's own files. These are not security findings but rather integrity tracking records. There are no code-smell detections, no obfuscation flags, no dependency vulnerabilities, and no manifest analysis warnings. This pattern is consistent with a legitimate, well-maintained language tool extension that has been properly analyzed and found to contain no security concerns.

Key Reasons

  • Zero malware signatures or IoC matches detected
  • All findings are benign file integrity hashes with info severity
  • Extension serves legitimate language tool purpose with justified access patterns
  • No credential access or network exfiltration findings

False Positive Considerations

  • metadata file hashes misclassified as findings
  • zero actual security detections in all threat categories
  • benign language server extension with standard bundled libraries

Reviewed 2026-05-24; recommended action: no action; model confidence 95%.

About This Extension

ZenStack is a toolkit that simplifies the development of a web app's backend. This plugin provides code editing experiences for its ZModel schema language. Features...

Frequently Asked Questions