Editor pluginEclipse

An Eclipse plugin can read your source before you open a file.

Eclipse plugins execute inside the workbench. Extuno diffs each update, then runs it in a sandbox and records what executes at startup, which files it reads, and what it sends out. Static, dynamic, and AI analysis run on every scan.

In shortTo check a Eclipse plugin for supply-chain risk, scan the published artifact, not just the source, and compare each new version against the last. Extuno runs static analysis, a dynamic sandbox, and AI review across every Eclipse release, then reports evidence on every finding.
Eclipse - live inspectionexample
com.acme.dark-theme 3.1.0
eclipse plugin
3.0.2->3.1.0
Static
Dynamic
AI
Analyzing update
What Extuno catches in Eclipse

Every finding is backed by evidence.

Each finding names the change, why it is dangerous, and the recommended action.

Diff finding

Startup hook execution

A plugin registers a startup hook that runs attacker code on launch.

Critical
Diff finding

Workspace file harvest

An update reads source and config files and uploads them.

Critical
Diff finding

New bundle dependency

The update pulls an unsigned bundle from an external update site.

Review
See it on a poisoned update

The startup hook fires before the workbench finishes loading

Extuno captures the workbench startup chain and the data leaving the host.

  • + Vulnerability and secret-leak testing on every version
  • + Static analysis reads the code without running it
  • + Dynamic sandbox runs it live and records behavior
  • + AI code analysis reads the full source and correlates the change against prior versions
How it works
  1. 1Launch workbench
  2. 2Plugin startup hook fires
  3. 3Scans workspace files
  4. 4Opens outbound socket
  5. 5Exfiltrates source + secrets

Scan your first Eclipse plugin free.

5 free credits on signup. One credit per scan, no card required.

FAQ

Common questions

Does Extuno support Eclipse?

Yes. Extuno scans Eclipse with static analysis, a dynamic sandbox, and AI code analysis, and diffs every version to catch one that was clean but poisoned through an update.

How does Extuno scan Eclipse?

Extuno acquires the published Eclipse artifact, reads it statically with 1100+ rules, runs it in a network-segmented sandbox, reviews the source with AI, and diffs it against the prior version. The finding names the file, the change, why it is dangerous, and the fix.

What does Extuno catch in Eclipse?

Leaked secrets, obfuscated or malicious code, dangerous permissions and APIs, exfiltration and command-and-control behavior, and the headline signal: a version that turns malicious after an update.