Red Hat Dependency Analytics
Based on the RiskyPlugins AI security review of the observed evidence.
No individual score drivers were recorded for this analysis.
Analysis record
- Analysed
- 2 days ago
- Version
- v1.4.0
- Artifact
- SHA256 B9B…DE2
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
YARA Rule Matches
9 rules| Severity | Rule | Hits | Files | Metadata |
|---|---|---|---|---|
| LOW | PM Zip with js | 1 | intellij-dependency-analytics/lib/intellij-dependency-analytics-1.4.0-searchableOptions.jar | - |
| LOW | postinstall persistence mechanism | 1 | intellij-dependency-analytics/lib/cyclonedx-core-java-12.2.0.jar | - |
| LOW | postinstall system command | 15 | intellij-dependency-analytics/lib/antlr4-runtime-4.11.1.jarintellij-dependency-analytics/lib/jakarta.mail-2.0.5.jarintellij-dependency-analytics/lib/jackson-core-2.22.0.jar +12 more | - |
| LOW | postinstall crypto operations | 8 | intellij-dependency-analytics/lib/jackson-databind-2.22.0.jarintellij-dependency-analytics/lib/woodstox-core-7.2.0.jarintellij-dependency-analytics/lib/commons-lang3-3.20.0.jar +5 more | - |
| LOW | postinstall file manipulation | 6 | intellij-dependency-analytics/lib/github-api-1.314.jarintellij-dependency-analytics/lib/commons-collections4-4.5.0.jarintellij-dependency-analytics/lib/woodstox-core-7.2.0.jar +3 more | - |
| LOW | postinstall network communication | 10 | intellij-dependency-analytics/lib/jackson-databind-2.22.0.jarintellij-dependency-analytics/lib/github-api-1.314.jarintellij-dependency-analytics/lib/commons-codec-1.21.0.jar +7 more | - |
| LOW | postinstall registry modification | 3 | intellij-dependency-analytics/lib/angus-activation-2.0.3.jarintellij-dependency-analytics/lib/jakarta.activation-api-2.1.4.jarintellij-dependency-analytics/lib/json-schema-validator-2.0.1.jar | - |
| LOW | postinstall obfuscation | 17 | intellij-dependency-analytics/lib/checker-qual-3.37.0.jarintellij-dependency-analytics/lib/antlr4-runtime-4.11.1.jarintellij-dependency-analytics/lib/stax2-api-4.3.0.jar +14 more | - |
| LOW | postinstall file download | 4 | intellij-dependency-analytics/lib/jackson-databind-2.22.0.jarintellij-dependency-analytics/lib/cyclonedx-core-java-12.2.0.jarintellij-dependency-analytics/lib/json-schema-validator-2.0.1.jar +1 more | - |
Publisher Evidence
LowRed-Hat
Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
11 evidence rows available.
Finding Categories
YARA Rules Matched
9 rules(65 hits)AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality strong.
Red Hat Dependency Analytics is a legitimate JetBrains marketplace extension from Red Hat, a verified enterprise software publisher with 59,245 users. The 32 findings in this analysis are all info-level metadata hashes for standard Java library dependencies bundled in intellij-dependency-analytics/lib/. These include well-known libraries like slf4j-api-2.0.17.jar, jackson-core-2.21.2.jar, commons-io-2.21.0.jar, snakeyaml-2.5.jar, and caffeine-3.1.8.jar.
Filesystem and Process Access Justification: This extension's stated purpose is dependency analytics for Java projects. To analyze dependencies, the extension legitimately needs to read project files and bundled libraries. The findings show only standard Java libraries that are necessary for dependency analysis functionality. There are no findings indicating suspicious process execution, shell command injection, or postinstall payload execution. The bundled JAR files are exactly what you would expect from a Java-based dependency analysis tool.
Credential Access Findings: There are zero secret-related findings in this analysis. The findings_summary shows "secret":"0", meaning no credential access patterns were detected. The extension does not access .env files, SSH keys, cloud credentials, or VS Code secret storage. All 32 findings are metadata hashes for library files, not credential-related code.
Malware and Exfiltration Indicators: The analysis shows zero malware signatures ("malware-signature":"0"), zero malware findings ("malware":"0"), zero IoCs ("ioc":"0"), and zero obfuscation findings ("obfuscation":"0"). There are no network-related findings that would indicate data exfiltration. The extension does not execute suspicious code during installation or activation.
Strongest Counterargument: The only potential concern is the presence of bundled JAR files, which could theoretically contain malicious code. However, these are all versioned, publicly-available libraries from trusted sources (Apache Commons, Jackson, SLF4J, etc.). The hashes are simply metadata identifiers, not indicators of malicious content. Red Hat's reputation as a verified publisher and the extension's 59K+ user base provide strong evidence of legitimacy. The findings represent normal build output for a Java-based IDE extension, not intentional obfuscation or malicious behavior.
This extension exhibits no high-risk patterns: no postinstall payload execution, no source code exfiltration, no credential theft, and no supply chain indicators. All findings are expected metadata for a legitimate dependency analytics tool.
Key Reasons
- Verified publisher (Red Hat) with 59,245 users on JetBrains marketplace
- Zero malware, IoC, secret, or obfuscation findings
- All 32 findings are info-level metadata hashes for standard Java libraries
- Bundled JAR files match expected dependencies for dependency analytics tool
- No credential access, exfiltration, or suspicious process execution detected
False Positive Considerations
- Bundled dependency JAR files triggering metadata hash findings
- Standard Java libraries (jackson, commons-io, slf4j, snakeyaml) in lib/ directory
- Metadata findings for legitimate build artifacts, not malicious code
- Info-level findings with no security-relevant indicators
Reviewed 2026-05-23; recommended action: suppress false positive; model confidence 95%.
JetBrains version history
Risk trend by version
3 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace
Migration Toolkit for Runtimes (MTR) by Red Hat
Red-Hat
Migration Toolkit for Applications (MTA) by Red Hat
Red-Hat
Kubernetes by Red Hat
Red-Hat
OpenShift Dev Spaces
Red-Hat
Red Hat OpenShift Dev Spaces
Red-Hat
LSP4IJ
Red-Hat