Subversion
From the RiskyPlugins AI security review of the observed evidence.
Analysis record
- Analysed
- Today
- Version
- v263.6259.38
- Artifact
- SHA256 163…4AB
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
YARA Rule Matches
8 rules| Severity | Rule | Hits | Files | Metadata |
|---|---|---|---|---|
| LOW | postinstall crypto operations | 2 | vcs-svn/lib/vcs-svn.jarvcs-svn/lib/intellij.libraries.sqlite.jar | - |
| LOW | postinstall file manipulation | 2 | vcs-svn/lib/vcs-svn.jarvcs-svn/lib/intellij.libraries.sqlite.jar | - |
| LOW | postinstall registry modification | 1 | vcs-svn/lib/vcs-svn.jar | - |
| LOW | postinstall obfuscation | 2 | vcs-svn/lib/vcs-svn.jarvcs-svn/lib/intellij.libraries.sqlite.jar | - |
| LOW | postinstall network communication | 2 | vcs-svn/lib/vcs-svn.jarvcs-svn/lib/intellij.libraries.sqlite.jar | - |
| LOW | postinstall system command | 2 | vcs-svn/lib/vcs-svn.jarvcs-svn/lib/intellij.libraries.sqlite.jar | - |
| LOW | postinstall file download | 2 | vcs-svn/lib/vcs-svn.jarvcs-svn/lib/intellij.libraries.sqlite.jar | - |
| LOW | postinstall persistence mechanism | 1 | vcs-svn/lib/vcs-svn.jar | - |
Publisher Evidence
HighJetBrains
Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
12 evidence rows available.
Finding Categories
YARA Rules Matched
8 rules(14 hits)AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality strong.
The Subversion extension, developed by JetBrains s.r.o., has a very low finding count, with only two metadata findings, both of which are informational and related to hashes of jar files (vcs-svn/lib/vcs-svn.jar and vcs-svn/lib/sqlite.jar). There are no malware signatures, IoC, or other threat indicators. The extension's purpose is related to version control system integration, which typically requires some level of filesystem and network access. However, given the lack of any suspicious findings and the developer being a well-known and reputable entity in the software development industry, the filesystem and network access required by this extension are likely justified by its stated purpose. The strongest counterargument to a benign verdict could be the potential for abuse of the required permissions, but given the extension's clear and legitimate purpose and the absence of any evidence suggesting malicious intent, this counterargument does not significantly impact the conclusion. Therefore, the extension's access to the filesystem and its ability to spawn processes are likely within the bounds of its intended functionality.
Key Reasons
- Low finding count with only informational metadata findings
- No malware signatures or threat indicators
- Developer is a reputable entity in the software development industry
- Extension's required permissions are likely justified by its purpose
Reviewed 2026-05-23; recommended action: no action; model confidence 90%.
JetBrains version history
Risk trend by version
109 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace