Time Tracking Dashboard Widgets
The AI review rates the findings as likely false positive, but the risk score (65/100) still counts them.
Analysis record
- Analysed
- Yesterday
- Version
- v1.0.1
- Artifact
- SHA256 5E5…969
- Source
- Findings (non-IoC)
Is Time Tracking Dashboard Widgets safe?
Time Tracking Dashboard Widgets is a set of JetBrains dashboard widgets for showing how much time you and your team have logged, plus an export for YouTrack work items. The extension declares no special permissions and the host list is empty. The only network-looking strings in the scan are fragments pulled out of minified widget code rather than real servers, like d3.select, which is a call into the d3 charting library, and hh.mm.ss, which is a time format.
The findings that look alarming are in widgets/time-tracking-report/main.js and widgets/youtrack-work-items-export/main.js, where the scanner flagged invisible unicode characters and indirect function calls. If those were hiding something, you would expect to see the characters decoded and run somewhere, or a download of more code. Neither shows up. Indirect calls such as (0, fn)() are what every bundler emits, and zero-width characters turn up in bundled string tables regularly. No malware signature matched, and no environment file, SSH key or cloud credential was read.
The scanner also tripped on a long pile of extracted hostnames that are really JavaScript property chains, things like line.zero, n-l.circle and pc.mc. That happens when a tool reads minified code and guesses at what looks like a domain. Read individually they are noise. The widgets are published by JetBrains itself, and fetching logged hours and drawing charts is what a time tracking widget is for.
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
YARA Rule Matches
13 rules| Severity | Rule | Hits | Files | Metadata |
|---|---|---|---|---|
| LOW | credential env files | 3 | widgets/youtrack-work-items-export/main.jswidgets/time-tracking-report/main.jswidgets/personal-time-tracking/main.js | - |
| LOW | postinstall persistence mechanism | 2 | widgets/youtrack-work-items-export/main.jswidgets/personal-time-tracking/main.js | - |
| LOW | postinstall crypto operations | 3 | widgets/youtrack-work-items-export/main.jswidgets/time-tracking-report/main.jswidgets/personal-time-tracking/main.js | - |
| LOW | postinstall file manipulation | 3 | widgets/youtrack-work-items-export/main.jswidgets/time-tracking-report/main.jswidgets/personal-time-tracking/main.js | - |
| LOW | postinstall registry modification | 3 | widgets/youtrack-work-items-export/main.jswidgets/time-tracking-report/main.jswidgets/personal-time-tracking/main.js | - |
| LOW | postinstall obfuscation | 3 | widgets/youtrack-work-items-export/main.jswidgets/time-tracking-report/main.jswidgets/personal-time-tracking/main.js | - |
| LOW | postinstall network communication | 3 | widgets/youtrack-work-items-export/main.jswidgets/time-tracking-report/main.jswidgets/personal-time-tracking/main.js | - |
| LOW | postinstall system command | 3 | widgets/youtrack-work-items-export/main.jswidgets/time-tracking-report/main.jswidgets/personal-time-tracking/main.js | - |
| LOW | OriginsNotVerified | 3 | widgets/youtrack-work-items-export/main.jswidgets/time-tracking-report/main.jswidgets/personal-time-tracking/main.js | - |
| LOW | postinstall file download | 3 | widgets/youtrack-work-items-export/main.jswidgets/time-tracking-report/main.jswidgets/personal-time-tracking/main.js | - |
| LOW | SQLInjection | 3 | widgets/youtrack-work-items-export/main.jswidgets/time-tracking-report/main.jswidgets/personal-time-tracking/main.js | - |
| LOW | NoUseWeakRandom | 3 | widgets/youtrack-work-items-export/main.jswidgets/time-tracking-report/main.jswidgets/personal-time-tracking/main.js | - |
| LOW | DebuggerStatementsShouldNotBeUsed | 1 | widgets/youtrack-work-items-export/main.js | - |
Network Indicators
Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.
Network indicators are queued for lazy loading
Scroll this section into view to load the detailed rows.
Publisher Evidence
HighJetBrains
Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
12 evidence rows available.
Finding Categories
YARA Rules Matched
13 rules(36 hits)AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality moderate.
Time Tracking Dashboard Widgets ships three JetBrains Space/YouTrack dashboard widgets: personal time tracking, a time tracking report, and a YouTrack work items export. Widgets are small web apps rendered in a dashboard iframe, and the extension declares no permissions. Nothing in the scan shows a postinstall step, a child process, or a file write.
Filesystem and process access
The three entry points, widgets/personal-time-tracking/main.js, widgets/time-tracking-report/main.js and widgets/youtrack-work-items-export/main.js, hold no evidence of reading workspace files or spawning processes. The manifest-analysis category is empty. For a widget that fetches logged hours from an API and draws a chart, that is the expected shape: HTTP requests plus DOM rendering.
Credential access
Nothing here reads .env, .ssh, cloud credentials or a secret store; the secret category is empty. The low-severity code-quality rules that fired are the generic set that matches bundled JavaScript. Malware-signature matches and tool-poisoning matches are both at zero.
The endpoint list
The endpoint list does not hold up. It contains d3.select, a call into the d3 charting library, hh.mm.ss, a time format string, and chains such as line.zero, n-l.circle, pc.mc, bn.day and er.as lifted from minified code. field-sample.yt sits alongside opera.mini and galaxy.nexus, which is the shape of string literals inside widget bundles. None of these reads as a service the widget contacts.
Obfuscation findings
Five medium hits: OBFUSCATION-function_indirect in all three main.js files and OBFUSCATION-invisible_unicode_payload in widgets/time-tracking-report/main.js and widgets/youtrack-work-items-export/main.js. function_indirect matches indirect call patterns such as (0, fn)() that every webpack or esbuild bundle emits. invisible_unicode_payload flags zero-width characters, which deserves attention in hand-written source and is common in bundled output, where those characters arrive from string literals or translation data. No finding shows the characters being decoded, concatenated into a URL, or passed to an eval or Function constructor.
Counterargument
The strongest case against this conclusion: an invisible unicode payload inside main.js, rather than a locale file, is somewhere a hidden string could sit, and JetBrains Space widgets are hosted web apps with network reach. That case fails on what is missing. There is no dynamic code load, no network finding, and no execution primitive in the same file, and a hidden payload with no sink does nothing. The characters sit in a bundle next to the library fragments they came from.
Key Reasons
- Publisher is JetBrains on the JetBrains marketplace, with no postinstall, process-spawn or manifest findings anywhere in the scan.
- All five obfuscation hits sit in bundled widget main.js files and match standard minifier output rather than hand-applied hiding.
- Endpoint list is dominated by non-host strings such as d3.select, hh.mm.ss and n-l.circle extracted from minified code.
- Secret category empty: no .env, .ssh, cloud credential or VS Code secret storage access.
- Zero malware-signature, tool-poisoning and network findings across the bundle.
False Positive Considerations
- IoC extractor reading minified JavaScript property chains (d3.select, hh.mm.ss, n-l.circle) as network domains
- Low-severity code-quality rules matching generic bundled JavaScript
- function_indirect obfuscation heuristic matching standard webpack/esbuild indirect call patterns
- Zero-width unicode characters inside bundled widget string data flagged as an invisible unicode payload
Reviewed 2026-10-01; recommended action: suppress false positive; model confidence 82%.
JetBrains version history
Risk trend by version
2 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace
Big Data Tools Azure
JetBrains
Gradle
JetBrains
Python Community Edition
JetBrains
Kotlin Onboarding: Collections
JetBrains
Web Browser (JCEF)
JetBrains
Kotlin Onboarding 2: Object-Oriented Programming
JetBrains