JetBrains Marketplace Verified

Wallaby

by 6d7ed77e-b276-469c-b88b-5bcc16fae09c · 134.8K users · 4.8 rating
ebd0d48d-f9c4-52c4-af6f-7334ccf01909 | v1.0.349
36/ 100
LOW risk
No change since v1.0.348
Analyst verdict
No high-risk signal observed

Based on the RiskyPlugins AI security review of the observed evidence.

Analysis record

Analysed
Yesterday
Version
v1.0.349
Artifact
SHA256 A8B…5D8
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

29 detail rows

YARA Rule Matches

9 rules
SeverityRuleHitsFilesMetadata
LOWPM Zip with js 1
wallaby-intellij/lib/wallaby-intellij-1.0.349-searchableOptions.jar
-
LOWpostinstall persistence mechanism 1
wallaby-intellij/lib/rxjava-3.1.8.jar
-
LOWpostinstall file download 1
wallaby-intellij/lib/wallaby-intellij-1.0.349.jar
-
LOWpostinstall crypto operations 2
wallaby-intellij/lib/kotlin-stdlib-2.4.0.jarwallaby-intellij/lib/rxjava-3.1.8.jar
-
LOWpostinstall file manipulation 2
wallaby-intellij/lib/rxjava-3.1.8.jarwallaby-intellij/lib/wallaby-intellij-1.0.349.jar
-
LOWJavaDropper 2
wallaby-intellij/lib/kotlin-stdlib-2.4.0.jarwallaby-intellij/lib/rxjava-3.1.8.jar
-
LOWpostinstall obfuscation 4
wallaby-intellij/lib/Java-WebSocket-1.5.3.jarwallaby-intellij/lib/kotlin-stdlib-2.4.0.jarwallaby-intellij/lib/rxjava-3.1.8.jar +1 more
-
LOWpostinstall network communication 3
wallaby-intellij/lib/Java-WebSocket-1.5.3.jarwallaby-intellij/lib/rxjava-3.1.8.jarwallaby-intellij/lib/wallaby-intellij-1.0.349.jar
-
LOWpostinstall system command 4
wallaby-intellij/lib/kotlin-stdlib-2.4.0.jarwallaby-intellij/lib/slf4j-api-2.0.6.jarwallaby-intellij/lib/rxjava-3.1.8.jar +1 more
-

Publisher Evidence

Low

6d7ed77e-b276-469c-b88b-5bcc16fae09c

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

88
Noisy-finding weight
x1.00
Publisher domain
wallabyjs.com
Observed
Store verification signal
Verified publisher
Verified
Extension portfolio
8
Portfolio

12 evidence rows available.

Finding Categories

YARA Rules Matched

9 rules(20 hits)
PM Zip with js postinstall persistence mechanism postinstall file download postinstall crypto operations postinstall file manipulation JavaDropper postinstall obfuscation postinstall network communication postinstall system command

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality moderate.

The Wallaby extension from Wallaby Team on the JetBrains marketplace shows no actual security concerns. All nine findings in the analysis are metadata hashes of bundled JAR dependencies located in the wallaby-intellij/lib/ directory. These include standard libraries such as kotlin-stdlib-2.2.0.jar, rxjava-3.1.8.jar, Java-WebSocket-1.5.3.jar, reactive-streams-1.0.4.jar, annotations-13.0.jar, slf4j-simple-2.0.6.jar, and slf4j-api-2.0.6.jar, plus the main extension JARs wallaby-intellij-1.0.347.jar and wallaby-intellij-1.0.347-searchableOptions.jar. These metadata findings are not security detections—they are simply package identifiers for legitimate dependencies that JetBrains extensions commonly bundle.

The extension's filesystem access is justified by its stated purpose as a test runner. Wallaby executes tests against source code, which requires reading project files and writing test results. The bundled dependencies support this functionality: rxjava-3.1.8.jar enables asynchronous test execution, Java-WebSocket-1.5.3.jar provides communication capabilities, and slf4j libraries handle logging. No credential-access findings target actual secrets such as .env files, .ssh directories, or cloud credentials. The metadata findings only reference JAR file hashes, not any sensitive configuration files or authentication tokens.

The strongest counterargument might be that bundled dependencies could theoretically contain malicious code. This concern does not apply here because the dependencies are standard, well-known libraries from public repositories, there are zero malware signatures detected in any bundled JARs, there are zero network indicators suggesting exfiltration behavior, and the extension has 130,195 users on the JetBrains marketplace indicating widespread adoption without reported security incidents. With zero IoC matches, zero malware signatures, zero obfuscation findings, and zero code-smell detections, this extension demonstrates the expected profile of a legitimate development tool. The metadata hashes are informational only and represent normal dependency packaging, not security concerns.

Key Reasons

  • All findings are metadata hashes of legitimate bundled dependencies
  • Zero malware signatures, IoC matches, or obfuscation findings
  • 130,195 users indicate widespread legitimate adoption
  • Standard test runner extension with justified file access

False Positive Considerations

  • Bundled JAR dependencies in lib/ directory
  • Metadata hashes are not security findings
  • No actual threat indicators present

Reviewed 2026-05-23; recommended action: no action; model confidence 95%.

JetBrains version history

Risk trend by version

5 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
36
Change since first
+15
Change from previous
No change
Versions:
First analyzed version
1.0.344
Apr 5, 2026
Risk range
21 to 36
Across analyzed versions
Latest analyzed version
1.0.349
Sep 23, 2026
Selected version
low
Version
v1.0.349
1 weeks ago
Risk score
36
Findings
29
Change vs previous
No change

Pick any point on the chart to explore that version's code below.

About This Extension

Wallaby.js is an intelligent test runner for JavaScript that continuously runs your tests. It reports code coverage and other results to your code editor immediately...

Frequently Asked Questions