Vienna Theme
The AI review rates the findings as likely false positive, but the risk score (44/100) still counts them.
Analysis record
- Analysed
- 2 days ago
- Version
- v2026.1.2
- Artifact
- SHA256 DFC…18C
- Source
- Findings (non-IoC)
Is Vienna Theme safe?
The Vienna Theme extension for JetBrains IDEs is a visual color scheme published by Codigrate. Its only job is to change how your editor looks. Because it is just a theme, it declares no special permissions and requires no access to your files, your terminal, or your system processes. The network endpoints it communicates with are limited to its own developer site at codigrate.com and the official JetBrains marketplace at plugins.jetbrains.com.
The automated scanner flagged 292 network indicators in this extension, which sounds like a lot. If you look at the specific findings, such as XIOC-URL-https://codigrate.com/util/color/DC5B26.png?width=18&height=18, you will see they are just links to small color swatch images hosted on the developer's website. The hex codes in those URLs are the actual colors the theme uses. Other flagged links just point to other themes made by the same developer. If these links were malicious, it would mean the theme was secretly phoning home to an attacker's server. In reality, they just point to the publisher's own assets.
The scanner tripped on the sheer number of URLs embedded in the theme's configuration files. It flagged every single web address it found without checking what those addresses actually do. Since all the network traffic goes to the developer's own color assets and the official plugin marketplace, there is no hidden data collection or malicious behavior here. The extension is completely safe to install if you like the color scheme.
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
YARA Rule Matches
2 rules| Severity | Rule | Hits | Files | Metadata |
|---|---|---|---|---|
| LOW | postinstall file manipulation | 1 | theme/vienna.xml | - |
| LOW | postinstall system command | 1 | theme/vienna.xml | - |
Publisher Evidence
LowCodigrate
Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
12 evidence rows available.
Finding Categories
YARA Rules Matched
2 rulesAI Security Report
AI Security Review
Evidence context: threat category none; evidence quality strong.
The "Vienna Theme" extension for JetBrains IDEs is a visual theme published by Codigrate. Its sole purpose is to change the color scheme of the editor interface. Consequently, it requires no special permissions, no filesystem access, and no process execution capabilities. The extension declares no host permissions and no workspace access, which is exactly what we expect from a purely cosmetic theme. It does not need to read your source code or execute build tools because it only modifies syntax highlighting colors and background shades.
The security findings in this bundle consist almost entirely of indicator-of-compromise extractions. Out of 299 total findings, 292 are medium-severity IoCs. However, examining the specific finding titles reveals that these are benign network requests for color assets. The findings are titled with URLs such as XIOC-URL-https://codigrate.com/util/color/DC5B26.png?width=18&height=18 and XIOC-URL-https://codigrate.com/util/color/3B3A45.png?width=18&height=18. These URLs point to the developer's own domain, codigrate.com, and are clearly fetching small color swatch images. The hex codes in the paths correspond directly to the colors being rendered in the editor. Other IoC findings point to https://plugins.jetbrains.com/plugin/34271-madrid-theme, which is simply a link to another theme by the same developer on the official JetBrains marketplace. The network endpoints list also includes plugins.jetbrains.com and www.corel.com. The Corel domain is likely referenced in bundled color palette assets or third-party design documentation included in the package, which is common for theme extensions that adapt popular color schemes.
There are zero malware signatures, zero secret-stealing code modules, and zero obfuscation techniques detected in the package. The two low-severity code-smell findings are standard noise that triggers on configuration files and basic JavaScript patterns. They do not indicate malicious behavior or hidden payloads. The extension does not attempt to read environment variables, access SSH keys, or interact with the IDE's secret storage. It simply registers a new color profile with the IDE and loads the associated image assets when the user selects it in the settings menu.
The strongest counterargument to clearing this extension is the sheer volume of IoC findings. A count of 292 network indicators looks alarming at a glance. However, the extraction tool simply flags any URL it finds in the extension package. For a theme extension that bundles or references hundreds of color swatches and cross-promotional links, this volume is entirely expected. The scanner tripped on the pattern of URLs without evaluating their context or destination. Since the URLs resolve to the publisher's own color assets and official marketplace pages, there is no evidence of external command-and-control infrastructure or unauthorized data collection. The extension is a standard visual theme doing exactly what a theme does, and the findings are an artifact of how the scanner processes theme assets.
Key Reasons
- All 292 IoC findings are URLs pointing to the developer's own color swatch images or official JetBrains marketplace pages.
- The extension declares no permissions and requires no filesystem or process access.
- No malware signatures, secret-stealing code, or obfuscation were detected.
- High finding count is an artifact of the scanner flagging every URL in the theme's configuration files.
False Positive Considerations
- XIOC extractor flagging benign color swatch URLs as network indicators
- High volume of embedded URLs in theme configuration files inflating IoC count
Reviewed 2026-10-01; recommended action: no action; model confidence 95%.
JetBrains version history
Risk trend by version
3 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace