Notepad++ Plugins

Columns++

05d7d784-6f0d-5e92-8dad-20ec63c8cfb6 | v1.3.3
57/ 100
MEDIUM risk
+22 since v1.3.1
Analyst verdict
Review before use

The AI review rates the findings as likely false positive, but the risk score (57/100) still counts them.

Analysis record

Analysed
1 months ago
Version
v1.3.3
Artifact
SHA256 CFA…008
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

6 detail rows

Finding Categories

1
Obfuscation

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality moderate.

The Columns++ Notepad++ extension provides legitimate text manipulation features including elastic tabstops, column alignment, and numeric calculations. The 101 IOC findings flagged in the evidence are exclusively documentation URLs extracted from files, including Wikipedia articles about encoding (https://en.wikipedia.org/wiki/Unicode, https://en.wikipedia.org/wiki/UTF-16, https://en.wikipedia.org/wiki/ASCII#Character_set), GitHub repository references (https://github.com/nlohmann/json), Boost documentation (https://www.boost.org/doc/libs/latest/libs/regex/), and Notepad++ user manual links (https://npp-user-manual.org/docs/searching/#single-character-matches). These URLs are embedded in documentation or help files, not active network destinations, and are expected for an extension dealing with text encoding and search functionality.

The 10 code-smell findings are classified as low severity and match standard C++ patterns in a native Notepad++ plugin. There are zero malware signature findings, zero network activity findings, zero secret/credential findings, and zero obfuscation findings. The extension has no evidence of credential theft (no .env, .ssh, or cloud credential access), no postinstall payload execution, and no data exfiltration patterns. The filesystem access required for column manipulation and text processing is justified by the extension's stated purpose.

The strongest counterargument is the zero user count, which could indicate a new or unverified upload. However, this metadata gap does not indicate malicious behavior—the actual code findings reveal only documentation references and standard C++ patterns. The extension is published by Randall Joseph Fellmy on the Notepad++ store, and while the version is unknown, the absence of any malicious indicators (malware signatures, suspicious network calls, credential access) confirms these findings are false positives from the IOC extractor flagging documentation URLs.

Key Reasons

  • All 101 IOC findings are benign documentation URLs, not active network destinations
  • Zero malware signatures or network activity detected
  • No credential access or secret findings
  • Filesystem access justified by text manipulation purpose

False Positive Considerations

  • Documentation URLs flagged as IoCs (Wikipedia, GitHub, Boost)
  • Code-smell findings on standard C++ patterns
  • High finding count from bundled documentation references

Reviewed 2026-04-27; recommended action: suppress false positive; model confidence 85%.

Notepad++ version history

Risk trend by version

2 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
57
Change since first
+22
Change from previous
+22
Versions:
First analyzed version
1.3.1
Apr 5, 2026
Risk range
36 to 57
Across analyzed versions
Latest analyzed version
1.3.3
Aug 10, 2026
Selected version
medium
Version
v1.3.3
1 months ago
Risk score
57
Findings
6
Change vs previous
+22

Pick any point on the chart to explore that version's code below.

Frequently Asked Questions