JetBrains Marketplace Verified

README Diagrams - Mermaid and Structurizr Preview

by jakub-jirak · 259 users
9d94f2c5-07a3-5601-b0ed-a2c812642815 | v2026.1.1
41/ 100
MEDIUM risk
No change since v2026.1.0
Analyst verdict
Review before use

The AI review rates the findings as likely false positive, but the risk score (41/100) still counts them.

Analysis record

Analysed
Yesterday
Version
v2026.1.1
Artifact
SHA256 598…873
Source
Findings (non-IoC)

Is README Diagrams - Mermaid and Structurizr Preview safe?

README Diagrams - Mermaid and Structurizr Preview is a JetBrains plugin that draws Mermaid and Structurizr diagrams inside your project README files so you can see them without leaving the editor. It reads the markdown already in your open project, and the scan lists no special permissions, no host permissions, and no endpoints it actually contacts.

The seventeen domain entries in the scan look alarming in bulk. They aren't. An entry like pom.properties is Maven build metadata that ships inside the plugin's own JAR, and entries like q7ɖ.lv, ߩ.st and u.sv are two-letter fragments with stray characters attached, the kind of string you get when a scanner splits compiled code on dots. If those were real addresses the plugin called, they would be worth worrying about. None of them is an address, and no network finding shows the plugin reaching anywhere.

There are also four low-severity code-smell matches, the class of rule that trips on just about any plugin using environment variables or crypto libraries. Nothing matched a malware signature, nothing showed obfuscation, and no access to .env files, SSH keys or cloud credentials turned up.

So the scanner tripped on a domain-extraction step that treats arbitrary dotted strings as websites. A plugin that previews diagrams has no reason to phone home, and nothing here shows it doing so.

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

4 detail rows

Publisher Evidence

Low

jakub-jirak

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

82
Noisy-finding weight
x1.00
Publisher domain
jakubjirak.com
Observed
Store verification signal
Verified publisher
Verified
Extension portfolio
24
Portfolio

12 evidence rows available.

Finding Categories

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality moderate.

This plugin renders Mermaid and Structurizr diagrams found in project README files, inside the JetBrains IDE. Publisher jakub-jirak, 259 users, version 2026.1.1. The job is to read markdown that already sits in the open project and draw it in a preview pane, which is the same file access any linter or formatter takes. Nothing in this scan goes further than that. The declared permissions list is empty, the host permissions list is empty, and no manifest-analysis result was produced at all. There is no postinstall step, no shell or child-process execution finding, no obfuscation finding, no dependency finding and no tool-poisoning finding.

Most of what the scan returns is one artifact of the extraction step. Seventeen entries are domain indicators from the XIOC extractor, every one of them filed under the synthetic path extracted_from_files. XIOC-DOMAIN-pom.properties is a Maven build file that ships inside a packaged plugin JAR, not a hostname. XIOC-DOMAIN-q7ɖ.lv, XIOC-DOMAIN-ߩ.st, XIOC-DOMAIN-u.sv, XIOC-DOMAIN-wrx.gf, XIOC-DOMAIN-zj.kh and their neighbors are two-letter TLD fragments with stray Unicode characters attached, the shape you get when a parser splits compiled output on dots. The endpoint list repeats those same strings, so it carries no new information. Not one network finding accompanies them, and a plugin that actually called a remote host would produce one.

Credential access is missing rather than benign. No secret finding appears, so there is no read of .env, no .git/config, no SSH key path, no cloud credential file and no use of the IDE's credential storage. The four remaining entries are low-severity code-smell matches, the category where broad rules fire on bundled build output and on ordinary references to environment variables or crypto APIs. None of them carries high or critical severity, and none names a file that a README previewer would have any reason to open.

The strongest argument against calling this clean is that no manifest analysis ran, so the plugin's declared permissions are unverified, and a previewer that resolves remote image links in a README could in principle reach out to a URL. Two things push back on that. Zero malware signatures matched anywhere in the archive, and a plugin fetching remote images would have produced a network finding, which it did not. The plugin name is distinctive and the publisher matches the author, so this is not a lookalike of a popular package. What remains is a small diagram tool plus a scanner that reads dotted strings as web addresses.

Key Reasons

  • All seventeen domain indicators come from the XIOC extractor under extracted_from_files, including pom.properties (a Maven build file) and two-letter TLD fragments with stray Unicode characters
  • Zero malware signatures, zero network findings, zero obfuscation findings and zero secret findings across the archive
  • No postinstall or child-process execution finding, and the permissions and host permissions lists are both empty
  • Four low-severity code-smell matches, the noisiest rule category, with no high or critical severity anywhere
  • Distinctive plugin name with the publisher matching the author, so no typosquat pattern

False Positive Considerations

  • XIOC domain extractor splitting compiled code and JAR contents on dots
  • Maven build metadata (pom.properties) misread as a hostname
  • Two-letter TLD fragments carrying stray Unicode characters
  • Generic low-severity code-smell rules firing on bundled build output

Reviewed 2026-10-01; recommended action: suppress false positive; model confidence 88%.

JetBrains version history

Risk trend by version

2 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
41
Change since first
No change
Change from previous
No change
Versions:
First analyzed version
2026.1.0
Jul 31, 2026
Risk range
41 to 41
Across analyzed versions
Latest analyzed version
2026.1.1
Sep 9, 2026
Selected version
medium
Version
v2026.1.1
3 weeks ago
Risk score
41
Findings
25
Change vs previous
No change

Pick any point on the chart to explore that version's code below.

About This Extension

Render Mermaid and Structurizr diagrams from your README Preview ```mermaid and ```structurizr fenced code blocks from Markdown files in a dedicated tool window...

Frequently Asked Questions