JetBrains Marketplace Verified

JetBrains Marketplace Licensing

by JetBrains · 118.0M users · 4.4 rating
c700305a-aabc-59f3-bc5f-a7e571e666ff | v263.6259.36
36/ 100
LOW risk
No change since v263.5701.34
Analyst verdict
No high-risk signal observed

Based on the RiskyPlugins AI security review of the observed evidence.

Analysis record

Analysed
Today
Version
v263.6259.36
Artifact
SHA256 7A3…09A
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

29 detail rows

YARA Rule Matches

10 rules
SeverityRuleHitsFilesMetadata
LOWpostinstall persistence mechanism 1
marketplace/lib/boot/marketplace-impl.jar
-
LOWpostinstall crypto operations 3
marketplace/lib/modules/intellij.marketplace.statistics.jarmarketplace/lib/boot/marketplace-bootstrap.jarmarketplace/lib/boot/marketplace-impl.jar
-
LOWpostinstall file manipulation 4
marketplace/lib/modules/intellij.marketplace.statistics.jarmarketplace/lib/boot/marketplace-bootstrap.jarmarketplace/lib/marketplace.jar +1 more
-
LOWpostinstall registry modification 1
marketplace/lib/boot/marketplace-impl.jar
-
LOWpostinstall obfuscation 3
marketplace/lib/boot/marketplace-bootstrap.jarmarketplace/lib/marketplace.jarmarketplace/lib/boot/marketplace-impl.jar
-
LOWpostinstall network communication 4
marketplace/lib/modules/intellij.marketplace.statistics.jarmarketplace/lib/boot/marketplace-bootstrap.jarmarketplace/lib/marketplace.jar +1 more
-
LOWpostinstall system command 4
marketplace/lib/modules/intellij.marketplace.statistics.jarmarketplace/lib/boot/marketplace-bootstrap.jarmarketplace/lib/marketplace.jar +1 more
-
LOWcredential generic tokens 1
marketplace/lib/boot/marketplace-impl.jar
-
LOWpostinstall file download 2
marketplace/lib/marketplace.jarmarketplace/lib/boot/marketplace-impl.jar
-
LOWDebuggerStatementsShouldNotBeUsed 1
marketplace/lib/boot/marketplace-impl.jar
-

Publisher Evidence

High

JetBrains

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

100
Noisy-finding weight
x0.50
Publisher domain
jetbrains.com
Trusted match
Store verification signal
Verified publisher
Verified
Extension portfolio
945
Portfolio

12 evidence rows available.

Finding Categories

YARA Rules Matched

10 rules(24 hits)
postinstall persistence mechanism postinstall crypto operations postinstall file manipulation postinstall registry modification postinstall obfuscation postinstall network communication postinstall system command credential generic tokens postinstall file download DebuggerStatementsShouldNotBeUsed

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality strong.

The JetBrains Marketplace Licensing extension has been analyzed, and the findings indicate that it is a legitimate development tool. The extension's purpose is to manage licensing for JetBrains products, and the filesystem and process access are justified by this purpose. The findings include several metadata hashes, which are expected for a legitimate extension. There are no indications of malicious behavior, such as postinstall payload execution, credential theft, or exfiltration. The strongest counterargument to this verdict would be the potential for the extension to access sensitive information, but the findings do not support this claim. The extension's access to the filesystem and processes is limited to what is necessary for its stated purpose. The user count for this extension is high, which suggests that it is a widely used and trusted tool. Overall, the findings suggest that this extension is likely a false positive, and its behavior is consistent with a legitimate development tool.

Key Reasons

  • legitimate development tool
  • justified filesystem and process access
  • no indications of malicious behavior

False Positive Considerations

  • bundled code
  • expected IDE behavior

Reviewed 2026-05-23; recommended action: no action; model confidence 90%.

JetBrains version history

Risk trend by version

45 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
36
Change since first
+1
Change from previous
No change
Versions:
First analyzed version
251.26927.99
Apr 24, 2026
Risk range
18 to 49
Across analyzed versions
Latest analyzed version
263.6259.36
Oct 1, 2026
Selected version
low
Version
v263.6259.36
Today
Risk score
36
Findings
29
Change vs previous
No change

Pick any point on the chart to explore that version's code below.

About This Extension

Licensing support for commercial plugins from JetBrains Marketplace.

Frequently Asked Questions