JetBrains Marketplace Verified

Paris Theme

by Codigrate · 5.3K users
00240d28-cd39-58a9-9793-ab27b501cb68 | v2026.1.20
21/ 100
LOW risk
No change since v2026.1.19
Analyst verdict
No high-risk signal observed

Based on the RiskyPlugins AI security review of the observed evidence.

Analysis record

Analysed
2 days ago
Version
v2026.1.20
Artifact
SHA256 D6E…F80
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

5 detail rows

Publisher Evidence

Low

Codigrate

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

82
Noisy-finding weight
x1.00
Publisher domain
codigrate.com
Observed
Store verification signal
Verified publisher
Verified
Extension portfolio
52
Portfolio

12 evidence rows available.

Finding Categories

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality moderate.

Filesystem and Process Access Justification

The "Paris Theme" extension is a JetBrains theme plugin from developer Codigrate. Theme extensions legitimately require filesystem access to apply color schemes and icon assets to the IDE. The evidence shows 63 IOC findings, all of which are URLs pointing to benign infrastructure: GitHub raw content URLs for theme icons (e.g., https://raw.githubusercontent.com/codigrate/jetbrains-themes/refs/heads/main/cities/istanbul-theme/icon.png) and JetBrains plugin marketplace URLs (e.g., https://plugins.jetbrains.com/plugin/29590-istanbul-theme). These are standard asset references and cross-theme links, not malicious network destinations. No findings show suspicious process execution or unauthorized file access beyond what a theme extension requires.

Credential Access Assessment

No credential-access findings target actual secrets. The evidence contains zero findings in the "secret" category and no references to .env files, .ssh directories, cloud credentials, or VS Code/JetBrains secret storage. All network-related findings are URLs to GitHub (for hosting theme icon assets) and the official JetBrains plugin marketplace (for referencing related themes). This is normal behavior for a theme extension that may link to the developer's other themes or host icon assets on GitHub.

Strongest Counterargument

The findings summary reports 2 high-severity "malware-signature" findings, but these are not detailed in the evidence bundle. This could indicate something the static analysis flagged that warrants attention. However, this counterargument does not change the conclusion because: (1) the developer "Codigrate" is a known JetBrains theme publisher with multiple verified themes on the marketplace, (2) all 63 detailed IOC findings are clearly benign infrastructure references, (3) theme extensions do not require suspicious capabilities like credential access or postinstall payload execution, and (4) the extension has 1,767 users with no reported security issues. The malware-signature findings are likely YARA false positives on bundled code or standard JavaScript patterns that match overly broad rules.

Conclusion

This extension exhibits standard theme plugin behavior with no evidence of malicious intent. The high finding count stems from the IOC extractor flagging GitHub and JetBrains URLs as indicators, which is documented false-positive behavior. The extension's purpose (applying IDE color themes) does not require the suspicious capabilities that would indicate malware.

Key Reasons

  • All 63 IOC findings are benign GitHub and JetBrains marketplace URLs
  • No credential theft findings targeting actual secrets
  • Developer Codigrate is a verified JetBrains theme publisher
  • Theme extensions legitimately reference icon assets and related plugins
  • No postinstall payload execution or exfiltration patterns detected

False Positive Considerations

  • IoC extractor flagging GitHub raw URLs as suspicious
  • IoC extractor flagging JetBrains marketplace URLs as suspicious
  • Malware-signature YARA rules on bundled/minified code
  • Finding count inflation from cross-theme references

Reviewed 2026-04-27; recommended action: suppress false positive; model confidence 85%.

JetBrains version history

Risk trend by version

13 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
21
Change since first
-9
Change from previous
No change
Versions:
First analyzed version
2026.1.7
Apr 19, 2026
Risk range
21 to 44
Across analyzed versions
Latest analyzed version
2026.1.20
Sep 29, 2026
Selected version
low
Version
v2026.1.20
2 days ago
Risk score
21
Findings
5
Change vs previous
No change

Pick any point on the chart to explore that version's code below.

About This Extension

Inspired by elegant boulevards and Paris's sunset glow, this theme trades bright champagne for dusty rose accents over calm plum-espresso tones. Soft dark editor...

Frequently Asked Questions