JetBrains Marketplace Verified

Quarkus Tools

by Red-Hat · 257.5K users · 3.7 rating
d01f2dd2-8cea-5c77-86ea-8d37ee19b2e0 | v2.6.1
36/ 100
LOW risk
No change since v2.6.0
Risk verdict
No high-risk signal observed

Score-based assessment (low risk, 36/100). Last analyst review covers version 2.5.0.

No individual score drivers were recorded for this analysis.

Analysis record

Analysed
Yesterday
Version
v2.6.1
Artifact
SHA256 448…482
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

138 detail rows
Showing 25 of 57 · highest severity first

YARA Rule Matches

10 rules
SeverityRuleHitsFilesMetadata
LOWpostinstall file download 3
intellij-quarkus/lib/flexmark-html2md-converter-0.64.8.jarintellij-quarkus/lib/server/com.redhat.qute.ls-uber.jarintellij-quarkus/lib/jackson-databind-2.18.2.jar
-
LOWPM Zip with js 2
intellij-quarkus/lib/intellij-quarkus-2.6.1.jarintellij-quarkus/lib/intellij-quarkus-2.6.1-searchableOptions.jar
-
LOWpostinstall persistence mechanism 6
intellij-quarkus/lib/intellij-quarkus-2.6.1.jarintellij-quarkus/lib/quarkus-core-3.15.1.jarintellij-quarkus/lib/annotations-24.0.1.jar +3 more
-
LOWpostinstall crypto operations 9
intellij-quarkus/lib/flexmark-util-collection-0.64.8.jarintellij-quarkus/lib/jctools-core-4.0.5.jarintellij-quarkus/lib/server/com.redhat.qute.ls-uber.jar +6 more
-
LOWpostinstall network communication 16
intellij-quarkus/lib/flexmark-0.64.8.jarintellij-quarkus/lib/smallrye-config-core-3.14.1.jarintellij-quarkus/lib/qute-core-3.30.1.jar +13 more
-
LOWpostinstall system command 13
intellij-quarkus/lib/guava-33.6.0-jre.jarintellij-quarkus/lib/org.eclipse.lsp4mp.ls-0.18.0.jarintellij-quarkus/lib/quarkus-core-deployment-3.15.1.jar +10 more
-
LOWpostinstall file manipulation 7
intellij-quarkus/lib/quarkus-arc-3.15.1.jarintellij-quarkus/lib/server/com.redhat.qute.ls-uber.jarintellij-quarkus/lib/intellij-quarkus-2.6.1.jar +4 more
-
LOWJavaDropper 3
intellij-quarkus/lib/server/com.redhat.qute.ls-uber.jarintellij-quarkus/lib/server/org.eclipse.lsp4mp.ls-uber.jarintellij-quarkus/lib/com.redhat.qute.ls-0.26.0-SNAPSHOT.jar
-
LOWpostinstall registry modification 8
intellij-quarkus/lib/server/com.redhat.quarkus.ls.jarintellij-quarkus/lib/server/com.redhat.qute.ls-uber.jarintellij-quarkus/lib/intellij-quarkus-2.6.1.jar +5 more
-
LOWpostinstall obfuscation 14
intellij-quarkus/lib/jackson-core-2.18.2.jarintellij-quarkus/lib/jsoup-1.17.1.jarintellij-quarkus/lib/guava-33.6.0-jre.jar +11 more
-

Publisher Evidence

Low

Red-Hat

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

97
Noisy-finding weight
x1.00
Publisher domain
redhat.com
Observed
Store verification signal
Verified publisher
Verified
Extension portfolio
64
Portfolio

11 evidence rows available.

Finding Categories

YARA Rules Matched

10 rules(81 hits)
postinstall file download PM Zip with js postinstall persistence mechanism postinstall crypto operations postinstall network communication postinstall system command postinstall file manipulation JavaDropper postinstall registry modification postinstall obfuscation

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality strong.

The Quarkus Tools extension, developed by Red Hat, is a legitimate development tool with broad access to the filesystem and process execution. The extension's stated purpose is to provide support for Quarkus, a Java framework, and its access to files and processes is justified by this purpose. The findings in the evidence bundle are primarily metadata findings, which are informational and do not indicate any malicious behavior. The extension does not have any findings related to malware, network activity, or obfuscation. The strongest counterargument to this verdict is that the extension has a large number of dependencies, which could potentially introduce security risks. However, the dependencies are all legitimate libraries and frameworks, and there is no evidence to suggest that they are being used for malicious purposes. The extension's access to credentials is also justified by its purpose, as it needs to access credentials to authenticate with Quarkus servers. In conclusion, the Quarkus Tools extension is a benign but powerful extension that is legitimate and does not pose a security risk. The findings in the evidence bundle are all related to metadata and do not indicate any malicious behavior. The extension's access to files and processes is justified by its purpose, and there is no evidence to suggest that it is being used for malicious purposes.

Key Reasons

  • legitimate development tool
  • justified access to files and processes
  • no malware or network activity findings

False Positive Considerations

  • metadata findings
  • dependency findings

Reviewed 2026-05-23; recommended action: no action; model confidence 90%.

JetBrains version history

Risk trend by version

4 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
36
Change since first
No change
Change from previous
No change
Versions:
First analyzed version
2.4.1
Apr 5, 2026
Risk range
36 to 36
Across analyzed versions
Latest analyzed version
2.6.1
Sep 2, 2026
Selected version
low
Version
v2.6.1
4 weeks ago
Risk score
36
Findings
138
Change vs previous
No change

Pick any point on the chart to explore that version's code below.

About This Extension

A plugin aimed at Quarkus based development, providing easy bootstrapping and code assist from Quarkus related assets and Qute. To provide those support, the plugin...

Frequently Asked Questions