Notepad++ Plugins

ImgTag

by salvom
06948378-533e-53e0-8547-9b82dad29971 | v2.0.1
59/ 100
MEDIUM risk
Analyst verdict
Review before use

The AI review rates the findings as likely false positive, but the risk score (59/100) still counts them.

Analysis record

Analysed
5 months ago
Version
v2.0.1
Artifact
SHA256 038…86C
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

5 detail rows

Network Indicators

Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.

12 total
...

Network indicators are queued for lazy loading

Scroll this section into view to load the detailed rows.

Finding Categories

1
Obfuscation
12
IoC Indicators

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality moderate.

Filesystem/Process Access Justification

The ImgTag plugin's stated purpose is to "Insert IMG tags, in your HTML document, using the Open File dialog box to select image files." This is a simple file picker and HTML generation tool. No findings in the evidence bundle indicate workspace file reads, process spawning, or network calls that would justify elevated access concerns. The 12 IoC findings do not reveal actual network behavior—they are XIOC extractor artifacts misidentifying text strings as domains and IPs.

Credential Access Findings

The findings bundle contains zero secret findings and zero credential-access findings. The IoC findings reference legitimate open-source infrastructure: freeimage.sourceforge.net (FreeImage library website), http://www.gnu.org/licenses/ (GNU license pages), and http://fsf.org/ (Free Software Foundation). These are documentation URLs likely embedded in the plugin's license or readme files, not credential exfiltration endpoints. No .env, .ssh, cloud credential, or secret storage access findings exist.

False Positive Analysis

The XIOC extractor generated classic false positives documented in CVEQ's known noise patterns:

  1. Version numbers misidentified as IPs: 4.0.0.0, 2.0.0.0, 2.0.1.0 match the extension version (2.0.1) and are not network addresses
  2. .NET namespace misidentified as domain: system.io is the System.IO namespace used in .NET file operations, not a domain
  3. Property file misidentified as domain: imgtag.properties is a configuration file, not a network endpoint
  4. Legitimate open-source project URLs: FreeImage, GNU, and FSF domains are benign infrastructure references

The 1 obfuscation finding and 1 critical finding lack detail in the evidence bundle. Given the plugin's simple purpose and the clear false-positive patterns in the IoC findings, these likely stem from bundled dependencies or XIOC noise.

Strongest Counterargument

The strongest argument against this verdict is the user_count: 0 combined with the 1 critical finding. Low adoption and a critical-severity finding could indicate a newly uploaded malicious plugin. However, the critical finding's nature is unspecified in the evidence, and the 0 user count is common for Notepad++ plugins on the OpenVSX mirror. The IoC findings are definitively false positives based on XIOC's documented extraction patterns, not evidence of malicious network behavior. Without specific evidence of postinstall payload execution, credential theft, or data exfiltration, the critical finding alone cannot justify a malicious verdict.

Conclusion

This is a legitimate HTML helper plugin with XIOC extractor false positives. The findings reflect version numbers, .NET namespaces, and open-source project URLs—not malicious infrastructure. Recommended action is to suppress these false positives.

Key Reasons

  • All IoC findings are XIOC false positives (version numbers, namespaces, property files)
  • No credential access or secret findings in evidence
  • Plugin purpose (IMG tag insertion) does not require suspicious capabilities
  • Referenced domains are legitimate open-source infrastructure

False Positive Considerations

  • XIOC version number to IP false positives (4.0.0.0, 2.0.0.0, 2.0.1.0)
  • .NET namespace System.IO misidentified as domain
  • Property file imgtag.properties misidentified as domain
  • Legitimate open-source URLs (GNU, FSF, FreeImage)

Reviewed 2026-05-08; recommended action: suppress false positive; model confidence 75%.

Frequently Asked Questions