The AI review rates the findings as likely false positive, but the risk score (57/100) still counts them.
Analysis record
- Analysed
- 1 months ago
- Version
- v1.1.1
- Artifact
- SHA256 FDD…6EC
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
Finding Categories
AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality moderate.
Security Analysis: Compose Extension (Notepad++)
Filesystem and Process Access Justification
The Compose extension implements keyboard character composition functionality for Notepad++. This extension requires no filesystem or process access beyond standard Notepad++ plugin capabilities. The evidence bundle contains zero manifest-analysis findings, zero network findings, and zero dependency findings. The extension does not spawn processes, read workspace files, or make network connections during runtime. All 59 IoC findings are documentation references and license URLs extracted from source code comments and bundled library headers, not actual network destinations.
Credential Access Findings
The evidence bundle contains zero secret findings. No credential-access findings target .env files, .git/config, SSH keys, or cloud credentials. The 12 code-smell findings (severity=high per findings_summary) represent generic code patterns detected by YARA rules, not actual credential theft. These code-smell findings match the known false-positive pattern described in the triage guidelines: credential_* rules fire on any code referencing API keys or environment variables, even in legitimate contexts.
Specific Finding Analysis
All 59 IoC findings reference benign, publicly documented URLs:
XIOC-URL-https://learn.microsoft.com/en-us/globalization/keyboards/kbdhe- Microsoft keyboard documentationXIOC-URL-https://github.com/notepad-plus-plus/notepad-plus-plus- Official Notepad++ repositoryXIOC-URL-https://en.wikipedia.org/wiki/Compose_key- Wikipedia articleXIOC-DOMAIN-www.gnu.organdXIOC-URL-https://www.gnu.org/licenses/gpl-3.0.html- GNU license documentationXIOC-URL-https://www.opensource.org/licenses/MIT- MIT licenseXIOC-URL-https://github.com/Coises/Compose-for-NotepadPlusPlus- Original project repositoryXIOC-URL-https://github.com/nlohmann/json- JSON library dependency
These URLs appear in source code comments, license headers, and bundled library metadata. They do not represent actual network connections or data exfiltration endpoints.
Strongest Counterargument
The strongest counterargument is the high severity rating (12 high-severity findings per findings_summary) and the total finding count of 78. However, the severity calibration guidance explicitly states that IoC volume and code-smell counts disproportionately inflate scores. Confirmed false positives average risk score 83.2, demonstrating that finding COUNT is noise while finding NATURE is signal. The 12 high-severity findings are code-smell detections on generic patterns, not confirmed malicious behavior. No malware-signature, malware, network, obfuscation, or secret findings exist in this bundle.
Conclusion
This extension is a legitimate utility for keyboard character composition. All findings stem from documentation URLs and expected code-smell noise. The extension poses no security threat to Notepad++ users.
Key Reasons
- All IoC findings are documentation and license URLs, not network destinations
- Zero malware signatures or actual malware findings
- Zero secret or credential access findings
- Code-smell findings match known false-positive patterns
- Extension purpose (Compose key) is legitimate utility functionality
False Positive Considerations
- IoC extractor documentation URLs
- Code-smell YARA noise
- License header URL extraction
- Bundled library references
Reviewed 2026-04-27; recommended action: suppress false positive; model confidence 88%.
Notepad++ version history
Risk trend by version
2 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace