Notepad++ Plugins

WebEdit

056f8007-eab7-5b46-bab5-f5484347f5b9 | v2.9.0.1
21/ 100
LOW risk
Analyst verdict
No high-risk signal observed

Based on the RiskyPlugins AI security review of the observed evidence.

No individual score drivers were recorded for this analysis.

Analysis record

Analysed
7 months ago
Version
v2.9.0.1
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

62 detail rows
Showing 25 of 62 · highest severity first

Finding Categories

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality moderate.

Filesystem/Process Access Justification

The WebEdit extension for Notepad++ provides code snippet expansion functionality. No filesystem or process access findings appear in the evidence bundle. The extension's stated purpose (expanding abbreviations into code snippets) does not require network connectivity or credential access, and no such capabilities are flagged in the findings.

Credential Access Findings

Zero secret/credential findings exist in this bundle. The findings_summary shows "secret":"0" and "code-smell":"0". No findings reference .env files, .ssh directories, cloud credentials, or VS Code secret storage. This is consistent with a legitimate code snippet tool that has no need to access sensitive developer credentials.

IoC Finding Analysis

All 31 IoC findings are documented false positives:

  1. IPv6 Fragments: Findings XIOC-IP-f::, XIOC-IP-::e, XIOC-IP-::a, XIOC-IP-::, and XIOC-IP-::fe are hex substrings from binary/minified code, not real IP addresses. These are well-documented XIOC extractor false positives per the CVEQ known issues.

  2. Version Numbers as IPs: XIOC-IP-4.2.1.0 and XIOC-IP-17.0.0.0 are version strings or private IP ranges, not malicious indicators. The 17.0.0.0 range is RFC 1918 private addressing.

  3. Legitimate Documentation URLs: XIOC-URL-https://aka.ms/dotnet-warnings/, XIOC-DOMAIN-aka.ms, XIOC-URL-https://github.com/dotnet/runtimea, and XIOC-DOMAIN-github.com reference official Microsoft .NET documentation and GitHub repositories. These are benign infrastructure domains commonly embedded in .NET/C# codebases.

Strongest Counterargument

The extension shows user_count: 0 with no download history, which could indicate a newly published supply chain attack vector. However, zero downloads alone does not constitute malicious behavior. The extension lacks any malware signatures ("malware-signature":"0", "malware":"0"), network behavior findings ("network":"0"), or obfuscation indicators ("obfuscation":"0"). A malicious Notepad++ plugin would require at least one of these capability indicators to execute payload delivery, credential theft, or data exfiltration. None exist.

Conclusion

The 93 total findings consist entirely of 31 IoC false positives and 62 info-level findings. No evidence of postinstall payload execution, credential theft, IP exfiltration, or supply chain poisoning exists. The findings represent standard XIOC extraction noise from binary DLL code, not malicious behavior.

Key Reasons

  • All 31 IoC findings are IPv6 fragments (f::, ::e, ::a) and legitimate Microsoft/GitHub documentation URLs
  • Zero malware signatures, network behavior, or credential access findings
  • Extension purpose (code snippet expansion) requires no network or credential capabilities
  • No obfuscation or code-smell findings in native DLL code

False Positive Considerations

  • XIOC IPv6 fragment extraction from binary code
  • Microsoft aka.ms documentation URLs flagged as IoCs
  • GitHub domain references in code
  • Version numbers misidentified as IP addresses

Reviewed 2026-04-27; recommended action: suppress false positive; model confidence 85%.

Frequently Asked Questions