Editor pluginJetBrains

A JetBrains plugin runs the moment you open a project.

Opening a project is enough to run arbitrary plugin code inside the IDE. Extuno diffs every update, then runs it live to see what fires at startup, what credentials it reads, and where the data goes. Every scan runs static, dynamic, and AI analysis.

In shortTo check a JetBrains plugin for supply-chain risk, scan the published artifact, not just the source, and compare each new version against the last. Extuno runs static analysis, a dynamic sandbox, and AI review across every JetBrains release, then reports evidence on every finding.
JetBrains - live inspectionexample
com.acme.bracket-colors 2.4
jetbrains plugin
2.3->2.4
Static
Dynamic
AI
Analyzing update
What Extuno catches in JetBrains

Every finding is backed by evidence.

Each finding names the change, why it is dangerous, and the recommended action.

Diff finding

Project-open execution

A plugin runs code the moment a project is opened, no action required.

Critical
Diff finding

SSH key access

An update reads ~/.ssh and posts key material off-host.

Critical
Diff finding

New network calls

The plugin contacts a host it never reached in prior releases.

Review
See it on a poisoned update

The plugin read ~/.ssh on project open

Extuno records the plugin's runtime behavior from startup to the first outbound beacon.

  • + Vulnerability and secret-leak testing on every version
  • + Static analysis reads the code without running it
  • + Dynamic sandbox runs it live and records behavior
  • + AI code analysis reads the full source and correlates the change against prior versions
How it works
  1. 1Open project
  2. 2Plugin loads at startup
  3. 3Reads ~/.ssh + env
  4. 4Spawns background process
  5. 5Exfiltrates key material

Scan your first JetBrains plugin free.

5 free credits on signup. One credit per scan, no card required.

FAQ

Common questions

Does Extuno support JetBrains?

Yes. Extuno scans JetBrains with static analysis, a dynamic sandbox, and AI code analysis, and diffs every version to catch one that was clean but poisoned through an update.

How does Extuno scan JetBrains?

Extuno acquires the published JetBrains artifact, reads it statically with 1100+ rules, runs it in a network-segmented sandbox, reviews the source with AI, and diffs it against the prior version. The finding names the file, the change, why it is dangerous, and the fix.

What does Extuno catch in JetBrains?

Leaked secrets, obfuscated or malicious code, dangerous permissions and APIs, exfiltration and command-and-control behavior, and the headline signal: a version that turns malicious after an update.