Is "WakaTime" on JetBrains Marketplace Safe to Install?

Verified
WakaTime · jetbrains · v16.0.0

Metrics, insights, and time tracking automatically generated from your programming activity. Installation 1. Inside your IDE, select Preferences -> Plugins -&gt...

Risk Assessment

Analyzed
100
out of 100
CRITICAL

250 security findings detected across all analyzers

JetBrains plugin analyzed via plugin.xml configuration and static code analysis

Severity Breakdown

0
Critical
23
High
165
Medium
0
Low
0
Info

Finding Categories

22
Malware Signatures
163
IoC Indicators

YARA Rules Matched

8 rules(22 hits)
JavaDropper postinstall obfuscation postinstall file manipulation postinstall network communication postinstall file download postinstall registry modification postinstall system command postinstall persistence mechanism

Plugin Configuration

JetBrains plugins declare dependencies and extension points in plugin.xml. Plugins can register actions, services, and listeners that run within the IDE process.

JETBRAINS-MANIFEST-APPLICATION-COMPONENT-com.wakatime.intellij.plugin.WakaTime
JETBRAINS-MANIFEST-ACTION-pluginMenu

About This Extension

Metrics, insights, and time tracking automatically generated from your programming activity. Installation 1. Inside your IDE, select Preferences -> Plugins -&gt...

Detailed Findings

85 total

YARA Rule Matches

8 rules

Indicators of Compromise

Network indicators, suspicious strings, and potential IoCs extracted during analysis

URLs
37
IP Addresses
16
Domains
108
Strings
163

All Indicators · 163

Domain
detected Domain: customeditormouselistener.java

XIOC detected Domain: customeditormouselistener.java

extracted_from_files

Domain
detected Domain: p.ec

XIOC detected Domain: p.ec

extracted_from_files

URL
detected URL: https://wakatime.com

XIOC detected URL: https://wakatime.com

extracted_from_files

IP
detected IP: ::e

XIOC detected IP: ::e

extracted_from_files

Domain
detected Domain: y.de

XIOC detected Domain: y.de

extracted_from_files

Domain
detected Domain: ꩡ.eg

XIOC detected Domain: ꩡ.eg

extracted_from_files

Domain
detected Domain: h.et

XIOC detected Domain: h.et

extracted_from_files

IP
detected IP: a::8

XIOC detected IP: a::8

extracted_from_files

IP
detected IP: ::67

XIOC detected IP: ::67

extracted_from_files

URL
detected URL: https://wakatime.com/)

XIOC detected URL: https://wakatime.com/)

extracted_from_files

URL
detected URL: https://api.wakatime.com

XIOC detected URL: https://api.wakatime.com

extracted_from_files

URL
detected URL: https://ctags.io/

XIOC detected URL: https://ctags.io/

extracted_from_files

URL
detected URL: https://wakatime.com/rider

XIOC detected URL: https://wakatime.com/rider

extracted_from_files

URL
detected URL: https://wakatime.com/rubymine

XIOC detected URL: https://wakatime.com/rubymine

extracted_from_files

URL
detected URL: https://wakatime.com/webstorm

XIOC detected URL: https://wakatime.com/webstorm

extracted_from_files

URL
detected URL: https://wakatime.com/api-key

XIOC detected URL: https://wakatime.com/api-key

extracted_from_files

URL
detected URL: https://wakatime.com/dashboard

XIOC detected URL: https://wakatime.com/dashboard

extracted_from_files

URL
detected URL: https://api.wakatime.com/api/v1/cli-missing?osname=

XIOC detected URL: https://api.wakatime.com/api/v1/cli-missing?osname=

extracted_from_files

URL
detected URL: https://api.github.com/repos/wakatime/wakatime-cli/releases/latest

XIOC detected URL: https://api.github.com/repos/wakatime/wakatime-cli/releases/latest

extracted_from_files

URL
detected URL: https://wakatime.com/android-studio

XIOC detected URL: https://wakatime.com/android-studio

extracted_from_files

URL
detected URL: https://wakatime.com/appcode

XIOC detected URL: https://wakatime.com/appcode

extracted_from_files

URL
detected URL: https://wakatime.com/clion

XIOC detected URL: https://wakatime.com/clion

extracted_from_files

URL
detected URL: https://wakatime.com/datagrip

XIOC detected URL: https://wakatime.com/datagrip

extracted_from_files

URL
detected URL: https://wakatime.com/goland

XIOC detected URL: https://wakatime.com/goland

extracted_from_files

URL
detected URL: https://wakatime.com/phpstorm

XIOC detected URL: https://wakatime.com/phpstorm

extracted_from_files

URL
detected URL: https://wakatime.com/pycharm

XIOC detected URL: https://wakatime.com/pycharm

extracted_from_files

URL
detected URL: https://github.com/wakatime/wakatime-cli/blob/develop/USAGE.md)

XIOC detected URL: https://github.com/wakatime/wakatime-cli/blob/develop/USAGE.md)

extracted_from_files

URL
detected URL: https://wakatime.com/static/img/ScreenShots/jetbrains-no-proxy-setting.png?v=1)

XIOC detected URL: https://wakatime.com/static/img/ScreenShots/jetbrains-no-proxy-setting.png?v=1)

extracted_from_files

URL
detected URL: https://wakatime.com/static/img/ScreenShots/jetbrains-wakatime-menu.png?v=1)

XIOC detected URL: https://wakatime.com/static/img/ScreenShots/jetbrains-wakatime-menu.png?v=1)

extracted_from_files

URL
detected URL: https://intellij-support.jetbrains.com/hc/en-us/articles/207241085-Locating-IDE-log-files)

XIOC detected URL: https://intellij-support.jetbrains.com/hc/en-us/articles/207241085-Locating-IDE-log-files)

extracted_from_files

URL
detected URL: https://github.com/wakatime/wakatime-cli/blob/develop/TROUBLESHOOTING.md).

XIOC detected URL: https://github.com/wakatime/wakatime-cli/blob/develop/TROUBLESHOOTING.md).

extracted_from_files

URL
detected URL: https://wakatime.com/

XIOC detected URL: https://wakatime.com/

extracted_from_files

URL
detected URL: https://wakatime.com/intellij-idea

XIOC detected URL: https://wakatime.com/intellij-idea

extracted_from_files

URL
detected URL: http://confluence.jetbrains.com/display/IDEADEV/Plugin+Compatibility+with+IntelliJ+Platform+Products

XIOC detected URL: http://confluence.jetbrains.com/display/IDEADEV/Plugin+Compatibility+with+IntelliJ+Platform+Products

extracted_from_files

URL
detected URL: https://img.shields.io/jetbrains/plugin/v/7425-wakatime.svg?style=flat-square&color=167dff&label=marketplace)](https://plugins.jetbrains.com/plugin/7425-wakatime)

XIOC detected URL: https://img.shields.io/jetbrains/plugin/v/7425-wakatime.svg?style=flat-square&color=167dff&label=marketplace)](https://plugins.jetbrains.com/plugin/7425-wakatime)

extracted_from_files

URL
detected URL: https://img.shields.io/jetbrains/plugin/d/7425-wakatime.svg?style=flat-square&color=167dff)](https://plugins.jetbrains.com/plugin/7425-wakatime)

XIOC detected URL: https://img.shields.io/jetbrains/plugin/d/7425-wakatime.svg?style=flat-square&color=167dff)](https://plugins.jetbrains.com/plugin/7425-wakatime)

extracted_from_files

URL
detected URL: https://wakatime.com/badge/github/wakatime/jetbrains-wakatime.svg?style=flat-square&color=167dff)](https://wakatime.com/intellij-idea)

XIOC detected URL: https://wakatime.com/badge/github/wakatime/jetbrains-wakatime.svg?style=flat-square&color=167dff)](https://wakatime.com/intellij-idea)

extracted_from_files

URL
detected URL: https://wakatime.com/settings#apikey)

XIOC detected URL: https://wakatime.com/settings#apikey)

extracted_from_files

URL
detected URL: https://wakatime.com).

XIOC detected URL: https://wakatime.com).

extracted_from_files

URL
detected URL: https://wakatime.com/static/img/ScreenShots/Screen-Shot-2016-03-21.png)

XIOC detected URL: https://wakatime.com/static/img/ScreenShots/Screen-Shot-2016-03-21.png)

extracted_from_files

Domain
detected Domain: github.com

XIOC detected Domain: github.com

extracted_from_files

URL
detected URL: https://github.com/wakatime/jetbrains-wakatime/blob/master/HISTORY.rst

XIOC detected URL: https://github.com/wakatime/jetbrains-wakatime/blob/master/HISTORY.rst

extracted_from_files

URL
detected URL: http://confluence.jetbrains.com/display/IDEADEV/Build+Number+Ranges

XIOC detected URL: http://confluence.jetbrains.com/display/IDEADEV/Build+Number+Ranges

extracted_from_files

IP
detected IP: c::

XIOC detected IP: c::

extracted_from_files

IP
detected IP: ::a

XIOC detected IP: ::a

extracted_from_files

Domain
detected Domain: wakatime-cli.s3-us-west-2.amazonaws.com

XIOC detected Domain: wakatime-cli.s3-us-west-2.amazonaws.com

extracted_from_files

Other
detected Email: [email protected]

XIOC detected Email: [email protected]

extracted_from_files

Other
detected Email: [email protected]

XIOC detected Email: [email protected]

extracted_from_files

Other
detected Email: [email protected]

XIOC detected Email: [email protected]

extracted_from_files

Other
detected Email: [email protected]

XIOC detected Email: [email protected]

extracted_from_files

Other
detected Email: [email protected]

XIOC detected Email: [email protected]

extracted_from_files

URL
detected URL: https://github.com/wakatime/jetbrains-wakatime#troubleshooting

XIOC detected URL: https://github.com/wakatime/jetbrains-wakatime#troubleshooting

extracted_from_files

Domain
detected Domain: 7.bd

XIOC detected Domain: 7.bd

extracted_from_files

Domain
detected Domain: r.gq

XIOC detected Domain: r.gq

extracted_from_files

Domain
detected Domain: e.sl

XIOC detected Domain: e.sl

extracted_from_files

Domain
detected Domain: o.za

XIOC detected Domain: o.za

extracted_from_files

Domain
detected Domain: o.ci

XIOC detected Domain: o.ci

extracted_from_files

Domain
detected Domain: 4.nu

XIOC detected Domain: 4.nu

extracted_from_files

Domain
detected Domain: ctags.io

XIOC detected Domain: ctags.io

extracted_from_files

Domain
detected Domain: i.cr

XIOC detected Domain: i.cr

extracted_from_files

Domain
detected Domain: i.ly

XIOC detected Domain: i.ly

extracted_from_files

Domain
detected Domain: lc.ch

XIOC detected Domain: lc.ch

extracted_from_files

Domain
detected Domain: ti-.jo

XIOC detected Domain: ti-.jo

extracted_from_files

Domain
detected Domain: ѕ.ax

XIOC detected Domain: ѕ.ax

extracted_from_files

Domain
detected Domain: e.py

XIOC detected Domain: e.py

extracted_from_files

Domain
detected Domain: 炊.ci

XIOC detected Domain: 炊.ci

extracted_from_files

Domain
detected Domain: ezgif.com

XIOC detected Domain: ezgif.com

extracted_from_files

Domain
detected Domain: ڵ8ӌay.bz

XIOC detected Domain: ڵ8ӌay.bz

extracted_from_files

Domain
detected Domain: s.pr

XIOC detected Domain: s.pr

extracted_from_files

Domain
detected Domain: 2.gf

XIOC detected Domain: 2.gf

extracted_from_files

Domain
detected Domain: z.io

XIOC detected Domain: z.io

extracted_from_files

Domain
detected Domain: rd.ki

XIOC detected Domain: rd.ki

extracted_from_files

Domain
detected Domain: v.tt

XIOC detected Domain: v.tt

extracted_from_files

Domain
detected Domain: api.github.com

XIOC detected Domain: api.github.com

extracted_from_files

Domain
detected Domain: heartbeat.java

XIOC detected Domain: heartbeat.java

extracted_from_files

Domain
detected Domain: localssltrustmanager.java

XIOC detected Domain: localssltrustmanager.java

extracted_from_files

Domain
detected Domain: pluginmenu.java

XIOC detected Domain: pluginmenu.java

extracted_from_files

IP
detected IP: b::

XIOC detected IP: b::

extracted_from_files

IP
detected IP: 2::e

XIOC detected IP: 2::e

extracted_from_files

Domain
detected Domain: wakatimestartupactivity.java

XIOC detected Domain: wakatimestartupactivity.java

extracted_from_files

Domain
detected Domain: wakatime.java

XIOC detected Domain: wakatime.java

extracted_from_files

URL
detected URL: https://wakatime.com/settings/account?apikey=true

XIOC detected URL: https://wakatime.com/settings/account?apikey=true

extracted_from_files

Domain
detected Domain: customstatusbar.java

XIOC detected Domain: customstatusbar.java

extracted_from_files

Domain
detected Domain: customvisiblearealistener.java

XIOC detected Domain: customvisiblearealistener.java

extracted_from_files

Domain
detected Domain: dependencies.java

XIOC detected Domain: dependencies.java

extracted_from_files

IP
detected Domain: wakatime-cli.zip

XIOC detected Domain: wakatime-cli.zip

extracted_from_files

URL
detected URL: https://github.com/wakatime/jetbrains-wakatime

XIOC detected URL: https://github.com/wakatime/jetbrains-wakatime

extracted_from_files

Domain
detected Domain: 5.dj

XIOC detected Domain: 5.dj

extracted_from_files

Domain
detected Domain: 0.ag

XIOC detected Domain: 0.ag

extracted_from_files

Domain
detected Domain: apikey.java

XIOC detected Domain: apikey.java

extracted_from_files

Domain
detected Domain: configfile.java

XIOC detected Domain: configfile.java

extracted_from_files

Domain
detected Domain: custombuildmanagerlistener.java

XIOC detected Domain: custombuildmanagerlistener.java

extracted_from_files

Domain
detected Domain: customcaretlistener.java

XIOC detected Domain: customcaretlistener.java

extracted_from_files

Domain
detected Domain: customdocumentlistener.java

XIOC detected Domain: customdocumentlistener.java

extracted_from_files

Domain
detected Domain: tw.rs

XIOC detected Domain: tw.rs

extracted_from_files

Domain
detected Domain: 뀦.kz

XIOC detected Domain: 뀦.kz

extracted_from_files

Domain
detected Domain: x.jm

XIOC detected Domain: x.jm

extracted_from_files

Domain
detected Domain: 8.hk

XIOC detected Domain: 8.hk

extracted_from_files

Domain
detected Domain: l.cn

XIOC detected Domain: l.cn

extracted_from_files

Domain
detected Domain: pcf.in

XIOC detected Domain: pcf.in

extracted_from_files

Domain
detected Domain: w.tf

XIOC detected Domain: w.tf

extracted_from_files

Domain
detected Domain: k.dm

XIOC detected Domain: k.dm

extracted_from_files

Domain
detected Domain: 3.ls

XIOC detected Domain: 3.ls

extracted_from_files

Domain
detected Domain: kŗ8.im

XIOC detected Domain: kŗ8.im

extracted_from_files

Domain
detected Domain: w.af

XIOC detected Domain: w.af

extracted_from_files

Domain
detected Domain: r.tc

XIOC detected Domain: r.tc

extracted_from_files

Domain
detected Domain: lb.mp

XIOC detected Domain: lb.mp

extracted_from_files

Domain
detected Domain: dg.sg

XIOC detected Domain: dg.sg

extracted_from_files

Domain
detected Domain: q.ai

XIOC detected Domain: q.ai

extracted_from_files

Domain
detected Domain: request.md

XIOC detected Domain: request.md

extracted_from_files

Domain
detected Domain: د8.cd

XIOC detected Domain: د8.cd

extracted_from_files

Domain
detected Domain: l.ly

XIOC detected Domain: l.ly

extracted_from_files

Domain
detected Domain: a.pa

XIOC detected Domain: a.pa

extracted_from_files

Domain
detected Domain: j.ax

XIOC detected Domain: j.ax

extracted_from_files

Domain
detected Domain: ex.at

XIOC detected Domain: ex.at

extracted_from_files

Domain
detected Domain: z.bw

XIOC detected Domain: z.bw

extracted_from_files

Domain
detected Domain: pa.ca

XIOC detected Domain: pa.ca

extracted_from_files

Domain
detected Domain: w.se

XIOC detected Domain: w.se

extracted_from_files

Domain
detected Domain: z.cy

XIOC detected Domain: z.cy

extracted_from_files

Domain
detected Domain: fs.tr

XIOC detected Domain: fs.tr

extracted_from_files

IP
detected IP: a::

XIOC detected IP: a::

extracted_from_files

IP
detected IP: d::

XIOC detected IP: d::

extracted_from_files

Domain
detected Domain: os.name

XIOC detected Domain: os.name

extracted_from_files

Domain
detected Domain: a.wf

XIOC detected Domain: a.wf

extracted_from_files

Domain
detected Domain: 侅.br

XIOC detected Domain: 侅.br

extracted_from_files

Domain
detected Domain: ws.tz

XIOC detected Domain: ws.tz

extracted_from_files

Domain
detected Domain: g.vn

XIOC detected Domain: g.vn

extracted_from_files

Domain
detected Domain: i.tt

XIOC detected Domain: i.tt

extracted_from_files

IP
detected IP: ::d6

XIOC detected IP: ::d6

extracted_from_files

Domain
detected Domain: settings.java

XIOC detected Domain: settings.java

extracted_from_files

Domain
detected Domain: vcs.log.tabs.properties

XIOC detected Domain: vcs.log.tabs.properties

extracted_from_files

Domain
detected Domain: cȉ.cl

XIOC detected Domain: cȉ.cl

extracted_from_files

Domain
detected Domain: 1.iq

XIOC detected Domain: 1.iq

extracted_from_files

Domain
detected Domain: ǜ.np

XIOC detected Domain: ǜ.np

extracted_from_files

Domain
detected Domain: 2.vu

XIOC detected Domain: 2.vu

extracted_from_files

Domain
detected Domain: h뤨.lk

XIOC detected Domain: h뤨.lk

extracted_from_files

Domain
detected Domain: usage.md

XIOC detected Domain: usage.md

extracted_from_files

Domain
detected Domain: troubleshooting.md

XIOC detected Domain: troubleshooting.md

extracted_from_files

Domain
detected Domain: r.jm

XIOC detected Domain: r.jm

extracted_from_files

Domain
detected Domain: readme.md

XIOC detected Domain: readme.md

extracted_from_files

Domain
detected Domain: 0.tc

XIOC detected Domain: 0.tc

extracted_from_files

Domain
detected Domain: e.yt

XIOC detected Domain: e.yt

extracted_from_files

Domain
detected Domain: e.om

XIOC detected Domain: e.om

extracted_from_files

Domain
detected Domain: wakatime.com

XIOC detected Domain: wakatime.com

extracted_from_files

Domain
detected Domain: confluence.jetbrains.com

XIOC detected Domain: confluence.jetbrains.com

extracted_from_files

Domain
detected Domain: api.wakatime.com

XIOC detected Domain: api.wakatime.com

extracted_from_files

Domain
detected Domain: com.intellij.modules.java

XIOC detected Domain: com.intellij.modules.java

extracted_from_files

Domain
detected Domain: img.shields.io

XIOC detected Domain: img.shields.io

extracted_from_files

Domain
detected Domain: intellij-support.jetbrains.com

XIOC detected Domain: intellij-support.jetbrains.com

extracted_from_files

Domain
detected Domain: plugins.jetbrains.com

XIOC detected Domain: plugins.jetbrains.com

extracted_from_files

Domain
detected Domain: linestats.java

XIOC detected Domain: linestats.java

extracted_from_files

IP
detected Domain: javafx-src.zip

XIOC detected Domain: javafx-src.zip

extracted_from_files

Domain
detected Domain: platform.java

XIOC detected Domain: platform.java

extracted_from_files

Domain
detected Domain: gmail.com

XIOC detected Domain: gmail.com

extracted_from_files

Domain
detected Domain: drdaeman.pp.ru

XIOC detected Domain: drdaeman.pp.ru

extracted_from_files

Domain
detected Domain: scondoo.de

XIOC detected Domain: scondoo.de

extracted_from_files

Domain
detected Domain: brightidea.com

XIOC detected Domain: brightidea.com

extracted_from_files

IP
detected IP: e::

XIOC detected IP: e::

extracted_from_files

IP
detected IP: 9::

XIOC detected IP: 9::

extracted_from_files

IP
detected IP: 6::

XIOC detected IP: 6::

extracted_from_files

Domain
detected Domain: vfg.by

XIOC detected Domain: vfg.by

extracted_from_files

Domain
detected Domain: x.na

XIOC detected Domain: x.na

extracted_from_files

Domain
detected Domain: customsavelistener.java

XIOC detected Domain: customsavelistener.java

extracted_from_files

Security Analysis Summary

Security Analysis Overview

WakaTime is a jetbrains extension published by WakaTime. Version 16.0.0 has been analyzed by the Risky Plugins security platform, receiving a risk score of 100/100 (CRITICAL risk) based on 250 security findings.

Risk Assessment

This extension presents critical security risk. Severe issues were detected, potentially including malware indicators, exposed secrets, or dangerous behaviors. Installation is strongly discouraged until these issues are addressed.

Findings Breakdown

  • High: 23 finding(s)
  • Medium: 165 finding(s)

What Was Analyzed

The security assessment covers multiple analysis categories:

  • Malware Detection: YARA rule matching against 2,400+ malware signatures
  • Secret Detection: Scanning for exposed API keys, tokens, and credentials
  • Static Analysis: Code-level security analysis for common vulnerability patterns
  • Network Analysis: Detection of suspicious network communications and endpoints
  • Obfuscation Detection: Identification of code obfuscation techniques

Developer Information

WakaTime is published by WakaTime on the jetbrains marketplace. The extension has approximately 2.0M users.

Recommendation

This extension is not recommended for installation without thorough manual review. Consider alternatives with lower risk scores, or contact the developer to address the identified security concerns.

Frequently Asked Questions