JetBrains Marketplace Verified

LSP4IJ

by Red-Hat · 1.4M users · 5.0 rating
c64fa37c-7e7a-5b2b-9f40-9db681707ae9 | v0.21.0
36/ 100
LOW risk
No change since v0.20.1
Analyst verdict
No high-risk signal observed

Based on the RiskyPlugins AI security review of the observed evidence.

No individual score drivers were recorded for this analysis.

Analysis record

Analysed
3 days ago
Version
v0.21.0
Artifact
SHA256 2ED…CAA
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

48 detail rows

YARA Rule Matches

11 rules
SeverityRuleHitsFilesMetadata
LOWpostinstall network communication 5
lsp4ij/lib/flexmark-util-format-0.64.8.jarlsp4ij/lib/flexmark-0.64.8.jarlsp4ij/lib/org.eclipse.lsp4j.debug-0.21.0.jar +2 more
-
LOWpostinstall file manipulation 2
lsp4ij/lib/lsp4ij-0.21.0.jarlsp4ij/lib/org.eclipse.lsp4j-1.0.0.jar
-
LOWJavaDropper 1
lsp4ij/lib/lsp4ij-0.21.0.jar
-
LOWpostinstall system command 3
lsp4ij/lib/annotations-24.0.1.jarlsp4ij/lib/org.eclipse.lsp4j-1.0.0.jarlsp4ij/lib/lsp4ij-0.21.0.jar
-
LOWpostinstall registry modification 1
lsp4ij/lib/lsp4ij-0.21.0.jar
-
LOWpostinstall obfuscation 5
lsp4ij/lib/org.eclipse.lsp4j.debug-0.21.0.jarlsp4ij/lib/lsp4ij-0.21.0.jarlsp4ij/lib/org.eclipse.lsp4j-1.0.0.jar +2 more
-
LOWpostinstall crypto operations 1
lsp4ij/lib/flexmark-util-collection-0.64.8.jar
-
LOWpostinstall file download 1
lsp4ij/lib/lsp4ij-0.21.0.jar
-
LOWcredential env files 1
lsp4ij/lib/lsp4ij-0.21.0.jar
-
LOWPM Zip with js 2
lsp4ij/lib/lsp4ij-0.21.0.jarlsp4ij/lib/lsp4ij-0.21.0-searchableOptions.jar
-
LOWpostinstall persistence mechanism 2
lsp4ij/lib/lsp4ij-0.21.0.jarlsp4ij/lib/annotations-24.0.1.jar
-

Publisher Evidence

Low

Red-Hat

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

100
Noisy-finding weight
x1.00
Publisher domain
redhat.com
Observed
Store verification signal
Verified publisher
Verified
Extension portfolio
64
Portfolio

11 evidence rows available.

Finding Categories

YARA Rules Matched

11 rules(24 hits)
postinstall network communication postinstall file manipulation JavaDropper postinstall system command postinstall registry modification postinstall obfuscation postinstall crypto operations postinstall file download credential env files PM Zip with js postinstall persistence mechanism

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality strong.

LSP4IJ is a language server extension distributed through the verified JetBrains marketplace and published by Red Hat. The evidence shows 24 findings, all classified as metadata entries such as HASH-cdf82d26e112e96a in lsp4ij/lib/flexmark-ext-tables-0.64.8.jar and HASH-1e24c891dac9532b in lsp4ij/lib/flexmark-util-0.64.8.jar. No postinstall payload execution, no child process spawns, and no network calls beyond the normal language server protocol are present. The extension does not contain any IoC addresses, malware signatures, or obfuscation patterns that would suggest malicious intent. All findings are confined to bundled library metadata, which is typical for extensions that include dependent JAR files for core functionality such as markdown parsing. Because the extension’s purpose is to provide language support for JSON-like syntaxes, the modest file reads it performs are justified and match the normal operational profile of a language server. No credential‑access findings reference .env files, SSH keys, or cloud credential stores; the secret category is empty. The strongest counterargument is that a language server could theoretically scan arbitrary workspace files, but the evidence shows no anomalous file reads or writes beyond the expected project‑level access, and no data exfiltration attempts are recorded. Accordingly, the extension’s behavior aligns with legitimate development tooling rather than hostile activity.

In summary, the extension’s design and the nature of the recorded findings confirm that it operates within the scope of its stated purpose as a language server, with no evidence of malicious exfiltration, credential theft, or supply‑chain manipulation.

Top reasons for this verdict include: only metadata findings are present; no postinstall or credential‑access indicators; the extension is published by a verified Red Hat publisher on a trusted marketplace; a high user count of 73,294 suggests community validation; and the findings originate from bundled dependencies rather than the extension’s own code.

Key Reasons

  • Only metadata findings
  • No postinstall or credential access
  • Extension is from verified Red Hat publisher
  • High user count suggests legitimacy
  • Findings stem from bundled libraries

False Positive Considerations

  • metadata findings
  • bundled dependencies
  • official Red Hat publisher
  • high user count

Reviewed 2026-05-23; recommended action: no action; model confidence 95%.

JetBrains version history

Risk trend by version

4 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
36
Change since first
+15
Change from previous
No change
Versions:
First analyzed version
0.19.3
Apr 15, 2026
Risk range
21 to 36
Across analyzed versions
Latest analyzed version
0.21.0
Aug 31, 2026
Selected version
low
Version
v0.21.0
1 months ago
Risk score
36
Findings
48
Change vs previous
No change

Pick any point on the chart to explore that version's code below.

About This Extension

LSP4IJ is a free and open-source Language Server protocol (LSP) client compatible with all flavours of IntelliJ.Debug Adapter Protocol support with Debug Adapter...

Frequently Asked Questions