JetBrains Marketplace Verified

IntelliPHP - AI Autocomplete for PHP

by devsense · 4.1K users · 4.4 rating
5e4576e7-3c52-5a18-b44a-aa17fe26a048 | v2024.2.0
65/ 100
MEDIUM risk
Analyst verdict
Review before use

The AI review rates the findings as likely false positive, but the risk score (65/100) still counts them.

Analysis record

Analysed
3 days ago
Version
v2024.2.0
Artifact
SHA256 A8C…7E6
Source
Findings (non-IoC)

Is IntelliPHP - AI Autocomplete for PHP safe?

IntelliPHP adds AI-powered autocompletion to PHP projects in JetBrains IDEs, and it ships the machine learning runtimes it needs inside the plugin itself. This build declares no special permissions, and the marketplace listing shows no host access. It carries native libraries such as intelliphp/lib/resources/runtimes/linux-x64/native/libonnxruntime.so, along with matching Windows and macOS builds, which are the standard ONNX and BlingFire pieces that turn your code into tokens and run the completion model on your machine.

The scanner flagged ten files under the title OBFUSCATION-supply_chain_binary. Those hits land on compiled binaries, and compiled binaries read as noise to a text scanner: symbol tables, lookup arrays, packed data, no readable structure. Nothing in those files hides behavior from a reviewer, and the install process does not fetch and run a payload from anywhere.

The long endpoint list is where the tooling slips up most. Entries like ai.onnx.training and allocator.cc are strings baked into the ONNX library, where they name an operator domain and a source file from the build. Fragments such as 1g.uz and 2e.sa got split out of compiled and minified code at the wrong character. There is no server behind those names. No malware signature matched, and no file like .env or an SSH key was read.

For a plugin running local machine learning over your PHP files, reading the workspace is the job. Devsense publishes through JetBrains Marketplace and signs its binaries per platform.

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

31 detail rows
Showing 25 of 31 · highest severity first

Publisher Evidence

Low

devsense

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

77
Noisy-finding weight
x1.00
Publisher domain
devsense.com
Observed
Store verification signal
Verified publisher
Verified
Extension portfolio
5
Portfolio

12 evidence rows available.

Finding Categories

10
Obfuscation

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality strong.

IntelliPHP is a JetBrains IDE plugin from devsense that provides AI code completion for PHP. The artifact carries its own inference stack, including intelliphp/lib/resources/runtimes/linux-x64/native/libonnxruntime.so, intelliphp/lib/resources/runtimes/win-x64/native/onnxruntime.dll, and intelliphp/lib/resources/runtimes/osx-arm64/native/libblingfiretokdll.dylib, with matching builds for win-arm64 and osx-x64. ONNX Runtime executes the completion model and BlingFire tokenizes source text, so the workspace reads and the process the plugin manages are the mechanism by which completions get produced. That access is the stated purpose of the tool.

Credential access is a non-issue here. The findings include nothing in the secret category, nothing matching .env, .ssh, .git/config, or cloud credential paths, and no manifest entry requesting VS Code or JetBrains secret storage. The 454 ioc entries read as exfiltration only if you count them. Read them instead: allocator.cc, approximation.cc, arena.cc, attention.cc, activations.cc, and ai.onnx.training. Those are C++ source filenames from the ONNX Runtime build plus a registered ONNX operator domain. Fragments like 1g.uz, 2e.sa, 2wn.sz, 8e.cc and 2oѫyl.gq are substrings the extractor carved out of compiled binaries and minified JavaScript mid-token. None of them is a host this plugin contacts, and the manifest declares no host permissions and no network endpoints.

The ten obfuscation findings all carry the title OBFUSCATION-supply_chain_binary and all point at native .so, .dylib and .dll files. Stripped, optimized, platform-targeted machine code trips entropy and structure heuristics by construction. That reflects how compilers emit binaries, not a concealment technique applied to source. No malware signature matched and no tool-poisoning finding was recorded. The 47 code-smell hits are broad rules that fire on ordinary JavaScript bundled with the plugin; none of them describes a behavior in this artifact.

A plugin that ships prebuilt native binaries and talks to an AI backend is a genuine supply-chain surface, and that is the strongest argument against this verdict. Anyone controlling the update channel could swap libonnxruntime.so and gain code execution inside the IDE. That exposure applies to every plugin bundling native code, and nothing here shows it has been exploited: the flags are generic, the endpoint list is extraction debris, and there is no credential read, no postinstall download, and no outbound destination the plugin actually uses.

The findings describe a machine learning runtime doing its job.

Key Reasons

  • All ten obfuscation hits are OBFUSCATION-supply_chain_binary on legitimate native ML runtimes (libonnxruntime.so, onnxruntime.dll, libblingfiretokdll.dylib)
  • 454 ioc entries are extraction fragments such as allocator.cc, attention.cc and ai.onnx.training from the ONNX Runtime build, not contacted hosts
  • Zero secret-category findings and no manifest request for credential or secret storage
  • No malware signature and no tool-poisoning findings recorded
  • JetBrains plugin with 4149 users from devsense, whose stated purpose requires workspace reads and local inference

False Positive Considerations

  • IoC extractor splitting C++ filenames and operator domain strings out of compiled ONNX binaries
  • Entropy and structure heuristics firing on stripped, optimized native libraries
  • Low-severity code-smell rules matching bundled JavaScript
  • Empty manifest permission sets leaving no grounded endpoint to compare against the ioc list

Reviewed 2026-09-30; recommended action: suppress false positive; model confidence 87%.

About This Extension

IntelliPHP is a local AI-powered extension for IntelliJ IDEs that enhances productivity and code development experience for PHP. Full-Line code completions IntelliPHP...

Frequently Asked Questions