JetBrains Marketplace Verified

Time Tracking Dashboard Widgets

by JetBrains · 46 users
aef1e802-6f2d-596d-88d2-f48b9d60e872 | v1.0.1
65/ 100
MEDIUM risk
No change since v1.0.0
Analyst verdict
Review before use

The AI review rates the findings as likely false positive, but the risk score (65/100) still counts them.

Analysis record

Analysed
Yesterday
Version
v1.0.1
Artifact
SHA256 5E5…969
Source
Findings (non-IoC)

Is Time Tracking Dashboard Widgets safe?

Time Tracking Dashboard Widgets is a set of JetBrains dashboard widgets for showing how much time you and your team have logged, plus an export for YouTrack work items. The extension declares no special permissions and the host list is empty. The only network-looking strings in the scan are fragments pulled out of minified widget code rather than real servers, like d3.select, which is a call into the d3 charting library, and hh.mm.ss, which is a time format.

The findings that look alarming are in widgets/time-tracking-report/main.js and widgets/youtrack-work-items-export/main.js, where the scanner flagged invisible unicode characters and indirect function calls. If those were hiding something, you would expect to see the characters decoded and run somewhere, or a download of more code. Neither shows up. Indirect calls such as (0, fn)() are what every bundler emits, and zero-width characters turn up in bundled string tables regularly. No malware signature matched, and no environment file, SSH key or cloud credential was read.

The scanner also tripped on a long pile of extracted hostnames that are really JavaScript property chains, things like line.zero, n-l.circle and pc.mc. That happens when a tool reads minified code and guesses at what looks like a domain. Read individually they are noise. The widgets are published by JetBrains itself, and fetching logged hours and drawing charts is what a time tracking widget is for.

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

51 detail rows

YARA Rule Matches

13 rules
SeverityRuleHitsFilesMetadata
LOWpostinstall crypto operations 3
widgets/youtrack-work-items-export/main.jswidgets/time-tracking-report/main.jswidgets/personal-time-tracking/main.js
-
LOWpostinstall file manipulation 3
widgets/youtrack-work-items-export/main.jswidgets/time-tracking-report/main.jswidgets/personal-time-tracking/main.js
-
LOWpostinstall registry modification 3
widgets/youtrack-work-items-export/main.jswidgets/time-tracking-report/main.jswidgets/personal-time-tracking/main.js
-
LOWpostinstall obfuscation 3
widgets/youtrack-work-items-export/main.jswidgets/time-tracking-report/main.jswidgets/personal-time-tracking/main.js
-
LOWpostinstall network communication 3
widgets/youtrack-work-items-export/main.jswidgets/time-tracking-report/main.jswidgets/personal-time-tracking/main.js
-
LOWpostinstall system command 3
widgets/youtrack-work-items-export/main.jswidgets/time-tracking-report/main.jswidgets/personal-time-tracking/main.js
-
LOWOriginsNotVerified 3
widgets/youtrack-work-items-export/main.jswidgets/time-tracking-report/main.jswidgets/personal-time-tracking/main.js
-
LOWDebuggerStatementsShouldNotBeUsed 1
widgets/youtrack-work-items-export/main.js
-
LOWpostinstall file download 3
widgets/time-tracking-report/main.jswidgets/personal-time-tracking/main.jswidgets/youtrack-work-items-export/main.js
-
LOWSQLInjection 3
widgets/time-tracking-report/main.jswidgets/personal-time-tracking/main.jswidgets/youtrack-work-items-export/main.js
-
LOWNoUseWeakRandom 3
widgets/time-tracking-report/main.jswidgets/personal-time-tracking/main.jswidgets/youtrack-work-items-export/main.js
-
LOWcredential env files 3
widgets/time-tracking-report/main.jswidgets/personal-time-tracking/main.jswidgets/youtrack-work-items-export/main.js
-
LOWpostinstall persistence mechanism 2
widgets/personal-time-tracking/main.jswidgets/youtrack-work-items-export/main.js
-

Network Indicators

Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.

165 total
...

Network indicators are queued for lazy loading

Scroll this section into view to load the detailed rows.

Publisher Evidence

High

JetBrains

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

99
Noisy-finding weight
x0.50
Publisher domain
jetbrains.com
Trusted match
Store verification signal
Verified publisher
Verified
Extension portfolio
945
Portfolio

12 evidence rows available.

Finding Categories

5
Obfuscation
165
IoC Indicators

YARA Rules Matched

13 rules(36 hits)
postinstall crypto operations postinstall file manipulation postinstall registry modification postinstall obfuscation postinstall network communication postinstall system command OriginsNotVerified DebuggerStatementsShouldNotBeUsed postinstall file download SQLInjection NoUseWeakRandom credential env files postinstall persistence mechanism

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality moderate.

Time Tracking Dashboard Widgets ships three JetBrains Space/YouTrack dashboard widgets: personal time tracking, a time tracking report, and a YouTrack work items export. Widgets are small web apps rendered in a dashboard iframe, and the extension declares no permissions. Nothing in the scan shows a postinstall step, a child process, or a file write.

Filesystem and process access

The three entry points, widgets/personal-time-tracking/main.js, widgets/time-tracking-report/main.js and widgets/youtrack-work-items-export/main.js, hold no evidence of reading workspace files or spawning processes. The manifest-analysis category is empty. For a widget that fetches logged hours from an API and draws a chart, that is the expected shape: HTTP requests plus DOM rendering.

Credential access

Nothing here reads .env, .ssh, cloud credentials or a secret store; the secret category is empty. The low-severity code-quality rules that fired are the generic set that matches bundled JavaScript. Malware-signature matches and tool-poisoning matches are both at zero.

The endpoint list

The endpoint list does not hold up. It contains d3.select, a call into the d3 charting library, hh.mm.ss, a time format string, and chains such as line.zero, n-l.circle, pc.mc, bn.day and er.as lifted from minified code. field-sample.yt sits alongside opera.mini and galaxy.nexus, which is the shape of string literals inside widget bundles. None of these reads as a service the widget contacts.

Obfuscation findings

Five medium hits: OBFUSCATION-function_indirect in all three main.js files and OBFUSCATION-invisible_unicode_payload in widgets/time-tracking-report/main.js and widgets/youtrack-work-items-export/main.js. function_indirect matches indirect call patterns such as (0, fn)() that every webpack or esbuild bundle emits. invisible_unicode_payload flags zero-width characters, which deserves attention in hand-written source and is common in bundled output, where those characters arrive from string literals or translation data. No finding shows the characters being decoded, concatenated into a URL, or passed to an eval or Function constructor.

Counterargument

The strongest case against this conclusion: an invisible unicode payload inside main.js, rather than a locale file, is somewhere a hidden string could sit, and JetBrains Space widgets are hosted web apps with network reach. That case fails on what is missing. There is no dynamic code load, no network finding, and no execution primitive in the same file, and a hidden payload with no sink does nothing. The characters sit in a bundle next to the library fragments they came from.

Key Reasons

  • Publisher is JetBrains on the JetBrains marketplace, with no postinstall, process-spawn or manifest findings anywhere in the scan.
  • All five obfuscation hits sit in bundled widget main.js files and match standard minifier output rather than hand-applied hiding.
  • Endpoint list is dominated by non-host strings such as d3.select, hh.mm.ss and n-l.circle extracted from minified code.
  • Secret category empty: no .env, .ssh, cloud credential or VS Code secret storage access.
  • Zero malware-signature, tool-poisoning and network findings across the bundle.

False Positive Considerations

  • IoC extractor reading minified JavaScript property chains (d3.select, hh.mm.ss, n-l.circle) as network domains
  • Low-severity code-quality rules matching generic bundled JavaScript
  • function_indirect obfuscation heuristic matching standard webpack/esbuild indirect call patterns
  • Zero-width unicode characters inside bundled widget string data flagged as an invisible unicode payload

Reviewed 2026-10-01; recommended action: suppress false positive; model confidence 82%.

JetBrains version history

Risk trend by version

2 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
65
Change since first
No change
Change from previous
No change
Versions:
First analyzed version
1.0.0
May 29, 2026
Risk range
65 to 65
Across analyzed versions
Latest analyzed version
1.0.1
Sep 30, 2026
Selected version
medium
Version
v1.0.1
Yesterday
Risk score
65
Findings
216
Change vs previous
No change

Pick any point on the chart to explore that version's code below.

About This Extension

A set of dashboard widgets for working with time tracking data from YouTrack. The set includes a widget for exporting work items and widgets for viewing personal work...

Frequently Asked Questions