JetBrains Marketplace Verified

Red Hat Dependency Analytics

by Red-Hat · 64.8K users · 3.6 rating
ce5f0eca-4dcb-516e-b951-e1a310bc75eb | v1.4.0
36/ 100
LOW risk
No change since v1.3.1
Analyst verdict
No high-risk signal observed

Based on the RiskyPlugins AI security review of the observed evidence.

No individual score drivers were recorded for this analysis.

Analysis record

Analysed
2 days ago
Version
v1.4.0
Artifact
SHA256 B9B…DE2
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

97 detail rows
Showing 25 of 32 · highest severity first

YARA Rule Matches

9 rules
SeverityRuleHitsFilesMetadata
LOWpostinstall file download 4
intellij-dependency-analytics/lib/cyclonedx-core-java-12.2.0.jarintellij-dependency-analytics/lib/json-schema-validator-2.0.1.jarintellij-dependency-analytics/lib/jakarta.mail-2.0.5.jar +1 more
-
LOWPM Zip with js 1
intellij-dependency-analytics/lib/intellij-dependency-analytics-1.4.0-searchableOptions.jar
-
LOWpostinstall persistence mechanism 1
intellij-dependency-analytics/lib/cyclonedx-core-java-12.2.0.jar
-
LOWpostinstall system command 15
intellij-dependency-analytics/lib/slf4j-api-2.0.17.jarintellij-dependency-analytics/lib/jackson-core-2.22.0.jarintellij-dependency-analytics/lib/commons-io-2.21.0.jar +12 more
-
LOWpostinstall crypto operations 8
intellij-dependency-analytics/lib/woodstox-core-7.2.0.jarintellij-dependency-analytics/lib/commons-lang3-3.20.0.jarintellij-dependency-analytics/lib/commons-codec-1.21.0.jar +5 more
-
LOWpostinstall file manipulation 6
intellij-dependency-analytics/lib/github-api-1.314.jarintellij-dependency-analytics/lib/commons-collections4-4.5.0.jarintellij-dependency-analytics/lib/woodstox-core-7.2.0.jar +3 more
-
LOWpostinstall network communication 10
intellij-dependency-analytics/lib/woodstox-core-7.2.0.jarintellij-dependency-analytics/lib/github-api-1.314.jarintellij-dependency-analytics/lib/jackson-databind-2.22.0.jar +7 more
-
LOWpostinstall registry modification 3
intellij-dependency-analytics/lib/jakarta.activation-api-2.1.4.jarintellij-dependency-analytics/lib/angus-activation-2.0.3.jarintellij-dependency-analytics/lib/json-schema-validator-2.0.1.jar
-
LOWpostinstall obfuscation 17
intellij-dependency-analytics/lib/checker-qual-3.37.0.jarintellij-dependency-analytics/lib/jackson-databind-2.22.0.jarintellij-dependency-analytics/lib/jackson-core-2.22.0.jar +14 more
-

Publisher Evidence

Low

Red-Hat

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

97
Noisy-finding weight
x1.00
Publisher domain
redhat.com
Observed
Store verification signal
Verified publisher
Verified
Extension portfolio
64
Portfolio

11 evidence rows available.

Finding Categories

YARA Rules Matched

9 rules(65 hits)
postinstall file download PM Zip with js postinstall persistence mechanism postinstall system command postinstall crypto operations postinstall file manipulation postinstall network communication postinstall registry modification postinstall obfuscation

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality strong.

Red Hat Dependency Analytics is a legitimate JetBrains marketplace extension from Red Hat, a verified enterprise software publisher with 59,245 users. The 32 findings in this analysis are all info-level metadata hashes for standard Java library dependencies bundled in intellij-dependency-analytics/lib/. These include well-known libraries like slf4j-api-2.0.17.jar, jackson-core-2.21.2.jar, commons-io-2.21.0.jar, snakeyaml-2.5.jar, and caffeine-3.1.8.jar.

Filesystem and Process Access Justification: This extension's stated purpose is dependency analytics for Java projects. To analyze dependencies, the extension legitimately needs to read project files and bundled libraries. The findings show only standard Java libraries that are necessary for dependency analysis functionality. There are no findings indicating suspicious process execution, shell command injection, or postinstall payload execution. The bundled JAR files are exactly what you would expect from a Java-based dependency analysis tool.

Credential Access Findings: There are zero secret-related findings in this analysis. The findings_summary shows "secret":"0", meaning no credential access patterns were detected. The extension does not access .env files, SSH keys, cloud credentials, or VS Code secret storage. All 32 findings are metadata hashes for library files, not credential-related code.

Malware and Exfiltration Indicators: The analysis shows zero malware signatures ("malware-signature":"0"), zero malware findings ("malware":"0"), zero IoCs ("ioc":"0"), and zero obfuscation findings ("obfuscation":"0"). There are no network-related findings that would indicate data exfiltration. The extension does not execute suspicious code during installation or activation.

Strongest Counterargument: The only potential concern is the presence of bundled JAR files, which could theoretically contain malicious code. However, these are all versioned, publicly-available libraries from trusted sources (Apache Commons, Jackson, SLF4J, etc.). The hashes are simply metadata identifiers, not indicators of malicious content. Red Hat's reputation as a verified publisher and the extension's 59K+ user base provide strong evidence of legitimacy. The findings represent normal build output for a Java-based IDE extension, not intentional obfuscation or malicious behavior.

This extension exhibits no high-risk patterns: no postinstall payload execution, no source code exfiltration, no credential theft, and no supply chain indicators. All findings are expected metadata for a legitimate dependency analytics tool.

Key Reasons

  • Verified publisher (Red Hat) with 59,245 users on JetBrains marketplace
  • Zero malware, IoC, secret, or obfuscation findings
  • All 32 findings are info-level metadata hashes for standard Java libraries
  • Bundled JAR files match expected dependencies for dependency analytics tool
  • No credential access, exfiltration, or suspicious process execution detected

False Positive Considerations

  • Bundled dependency JAR files triggering metadata hash findings
  • Standard Java libraries (jackson, commons-io, slf4j, snakeyaml) in lib/ directory
  • Metadata findings for legitimate build artifacts, not malicious code
  • Info-level findings with no security-relevant indicators

Reviewed 2026-05-23; recommended action: suppress false positive; model confidence 95%.

JetBrains version history

Risk trend by version

3 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
36
Change since first
-4
Change from previous
No change
Versions:
First analyzed version
1.2.0
Apr 5, 2026
Risk range
36 to 40
Across analyzed versions
Latest analyzed version
1.4.0
Sep 29, 2026
Selected version
low
Version
v1.4.0
2 days ago
Risk score
36
Findings
97
Change vs previous
No change

Pick any point on the chart to explore that version's code below.

About This Extension

Overview Red Hat Dependency Analytics (RHDA) plugin gives you awareness to security concerns within your software supply chain while you build your application. NOTE...

Frequently Asked Questions