JetBrains Marketplace Verified

Meta Horizon

by meta · 5.3K users · 4.4 rating
ac45a5ee-a8c3-5aa1-8f7a-d2bfaec1463e | v252.2.0.1.64
55/ 100
MEDIUM risk
No change since v252.2.0.1.49
Analyst verdict
Review before use

The AI review rates the findings as likely false positive, but the risk score (55/100) still counts them.

Analysis record

Analysed
Today
Version
v252.2.0.1.64
Artifact
SHA256 F58…8EA
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

1000 detail rows
Showing 25 of 1000 · highest severity first

Publisher Evidence

Low

meta

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

77
Noisy-finding weight
x1.00
Publisher domain
meta.com
Observed
Store verification signal
Verified publisher
Verified
Extension portfolio
6
Portfolio

12 evidence rows available.

Finding Categories

Plugin Configuration

JetBrains plugins declare dependencies and extension points in plugin.xml. Plugins can register actions, services, and listeners that run within the IDE process.

JETBRAINS-MANIFEST-APPLICATION-SERVICE-com.horizon.plugin.telemetry.session.TelemetrySessionManager
JETBRAINS-MANIFEST-PROJECT-SERVICE-com.horizon.plugin.data.ProjectDataProvider
JETBRAINS-MANIFEST-ACTION-com.horizon.plugin.resourcescreen.action.OpenDeveloperSupportRequestAction.toolsMenu
JETBRAINS-MANIFEST-ACTION-com.horizon.plugin.resourcescreen.action.OpenCommunityHelpAction.toolsMenu
JETBRAINS-MANIFEST-ACTION-com.horizon.plugin.actions.NewProjectAction
JETBRAINS-MANIFEST-ACTION-com.horizon.plugin.actions.SettingsAction.toolsMenu

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality strong.

This extension is a legitimate JetBrains plugin from Meta for their Horizon development platform. The analysis reveals no actual security concerns despite the high finding count.

Filesystem and Process Access Justification

The extension's class file paths confirm it is a development tool for Meta's Horizon platform, with components in com/horizon/plugin/ui/ for user interface elements, com/horizon/plugin/inspection/ for code inspection functionality, com/horizon/plugin/authentication/ for authentication handling, and com/horizon/plugin/telemetry/ for telemetry collection. These are standard components for an IDE plugin that provides development tooling. The QuestPermissionInspection class at com/horizon/plugin/inspection/QuestPermissionInspection$AndroidManifestQuickFix.class indicates the extension performs Android manifest permission inspections, which justifies read access to project files. The TelemetryConsentPanel class shows proper consent handling for telemetry collection.

Credential and Secret Access

Zero credential-related findings were detected. The findings summary shows "secret":"0" with no code-smell findings matching credential access patterns. The telemetry classes found (PluginEditorEvent, WelcomeDialogImpression, NoOpDeveloperTelemetry) are standard telemetry components that collect usage metadata, not source code or credentials. There are no findings indicating access to .env files, SSH keys, cloud credentials, or VS Code secret storage.

Strongest Counterargument

The two high-severity findings might suggest concern. However, without detailed evidence of what triggered these severities, and given that all 1,412 findings are metadata hashes on compiled Java class files with zero threat indicators (ioc=0, malware-signature=0, malware=0, obfuscation=0), this does not indicate malicious behavior. The findings are file hashes from the analysis pipeline, not security detections. Meta is a verified publisher on the JetBrains marketplace with 3,896 users, and the extension version (253.2.0.1.40) follows standard versioning for enterprise software.

Conclusion

This is a benign development tool. The high finding count is entirely metadata hashes from compiled Java bytecode, which is expected for any substantial IDE extension. No evidence of malicious behavior, credential theft, or data exfiltration exists.

Key Reasons

  • Zero threat indicators across all security categories (ioc, malware, obfuscation, secret, network)
  • All 1,412 findings are metadata hashes on compiled class files, not security detections
  • Verified publisher (Meta) on official JetBrains marketplace with 3,896 users
  • Class file paths indicate legitimate development tooling for Horizon platform

False Positive Considerations

  • Metadata hashes on compiled Java class files counted as findings
  • No actual security findings despite high total count
  • Standard IDE plugin components flagged as findings

Reviewed 2026-05-24; recommended action: suppress false positive; model confidence 95%.

JetBrains version history

Risk trend by version

4 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
55
Change since first
No change
Change from previous
No change
Versions:
First analyzed version
253.2.0.1.29
Apr 5, 2026
Risk range
55 to 55
Across analyzed versions
Latest analyzed version
252.2.0.1.64
Sep 24, 2026
Selected version
medium
Version
v252.2.0.1.64
1 weeks ago
Risk score
55
Findings
2041
Change vs previous
No change

Pick any point on the chart to explore that version's code below.

About This Extension

Build and test Android apps for Meta VR devices using the Meta VR Plugin for Android Studio, which includes: New project template for Android apps compatible with Meta...

Frequently Asked Questions