Notepad++ Plugins

Compose

1c411a99-7c47-5ac1-8bda-f5b8f05d5d92 | v1.1.1
57/ 100
MEDIUM risk
+22 since v1.1
Analyst verdict
Review before use

The AI review rates the findings as likely false positive, but the risk score (57/100) still counts them.

Analysis record

Analysed
1 months ago
Version
v1.1.1
Artifact
SHA256 FDD…6EC
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

8 detail rows

Finding Categories

1
Obfuscation

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality moderate.

Security Analysis: Compose Extension (Notepad++)

Filesystem and Process Access Justification

The Compose extension implements keyboard character composition functionality for Notepad++. This extension requires no filesystem or process access beyond standard Notepad++ plugin capabilities. The evidence bundle contains zero manifest-analysis findings, zero network findings, and zero dependency findings. The extension does not spawn processes, read workspace files, or make network connections during runtime. All 59 IoC findings are documentation references and license URLs extracted from source code comments and bundled library headers, not actual network destinations.

Credential Access Findings

The evidence bundle contains zero secret findings. No credential-access findings target .env files, .git/config, SSH keys, or cloud credentials. The 12 code-smell findings (severity=high per findings_summary) represent generic code patterns detected by YARA rules, not actual credential theft. These code-smell findings match the known false-positive pattern described in the triage guidelines: credential_* rules fire on any code referencing API keys or environment variables, even in legitimate contexts.

Specific Finding Analysis

All 59 IoC findings reference benign, publicly documented URLs:

  • XIOC-URL-https://learn.microsoft.com/en-us/globalization/keyboards/kbdhe - Microsoft keyboard documentation
  • XIOC-URL-https://github.com/notepad-plus-plus/notepad-plus-plus - Official Notepad++ repository
  • XIOC-URL-https://en.wikipedia.org/wiki/Compose_key - Wikipedia article
  • XIOC-DOMAIN-www.gnu.org and XIOC-URL-https://www.gnu.org/licenses/gpl-3.0.html - GNU license documentation
  • XIOC-URL-https://www.opensource.org/licenses/MIT - MIT license
  • XIOC-URL-https://github.com/Coises/Compose-for-NotepadPlusPlus - Original project repository
  • XIOC-URL-https://github.com/nlohmann/json - JSON library dependency

These URLs appear in source code comments, license headers, and bundled library metadata. They do not represent actual network connections or data exfiltration endpoints.

Strongest Counterargument

The strongest counterargument is the high severity rating (12 high-severity findings per findings_summary) and the total finding count of 78. However, the severity calibration guidance explicitly states that IoC volume and code-smell counts disproportionately inflate scores. Confirmed false positives average risk score 83.2, demonstrating that finding COUNT is noise while finding NATURE is signal. The 12 high-severity findings are code-smell detections on generic patterns, not confirmed malicious behavior. No malware-signature, malware, network, obfuscation, or secret findings exist in this bundle.

Conclusion

This extension is a legitimate utility for keyboard character composition. All findings stem from documentation URLs and expected code-smell noise. The extension poses no security threat to Notepad++ users.

Key Reasons

  • All IoC findings are documentation and license URLs, not network destinations
  • Zero malware signatures or actual malware findings
  • Zero secret or credential access findings
  • Code-smell findings match known false-positive patterns
  • Extension purpose (Compose key) is legitimate utility functionality

False Positive Considerations

  • IoC extractor documentation URLs
  • Code-smell YARA noise
  • License header URL extraction
  • Bundled library references

Reviewed 2026-04-27; recommended action: suppress false positive; model confidence 88%.

Notepad++ version history

Risk trend by version

2 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
57
Change since first
+22
Change from previous
+22
Versions:
First analyzed version
1.1
Apr 5, 2026
Risk range
36 to 57
Across analyzed versions
Latest analyzed version
1.1.1
Aug 10, 2026
Selected version
medium
Version
v1.1.1
1 months ago
Risk score
57
Findings
8
Change vs previous
+22

Pick any point on the chart to explore that version's code below.

Frequently Asked Questions