JetBrains Marketplace Verified

All In One Themes

by Codigrate · 2.7K users · 4.8 rating
2c76ea7a-0b74-5096-97d1-7472b2447d7f | v2026.1.23
47/ 100
MEDIUM risk
No change since v2026.1.22
Analyst verdict
Review before use

The AI review rates the findings as likely false positive, but the risk score (47/100) still counts them.

Analysis record

Analysed
2 days ago
Version
v2026.1.23
Artifact
SHA256 91F…F64
Source
Findings (non-IoC)

Is All In One Themes safe?

All In One Themes is a pack of color themes for JetBrains IDEs, published by Codigrate. It declares no special permissions. It talks to codigrate.com, where it pulls small preview images such as codigrate.com/util/color/DCA225.png?width=18&height=18, and to plugins.jetbrains.com, the marketplace's own update service. The hex code in each image path is a color, so the plugin is downloading the swatches it shows when you pick a theme.

The scan found no file reads outside the plugin's own resources, no command execution and no access to credential files. The items that look like alerts are those image URLs plus one string, bash.here, pulled out of the bundled code. If that string sat next to code that runs a shell command, it would mean the plugin could execute things on your machine. Nothing points to that: no file path, no finding title and no command-execution result goes with it, and the rest of the network traffic is the publisher plus the marketplace.

The remaining alerts are pattern matches that fire on bundled JavaScript. The rules behind them look for things like fs, exec and process.env, which show up in nearly every extension that ships a compiled settings page, even when it only draws themes. A long list of address hits sounds like a lot until you see they are all one host serving one color after another.

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

167 detail rows
Showing 25 of 85 · highest severity first

YARA Rule Matches

3 rules
SeverityRuleHitsFilesMetadata
LOWpostinstall persistence mechanism 2
META-INF/plugin.xmlMETA-INF/plugin 7.xml
-
LOWpostinstall system command 40
theme/nature/reynisfjara.xmltheme/nature/salda.xmltheme/cities/madrid 2.xml +37 more
-
LOWpostinstall file manipulation 40
theme/nature/sakura.xmltheme/nature/reynisfjara 2.xmltheme/cities/tallinn.xml +37 more
-

Network Indicators

Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.

246 total
...

Network indicators are queued for lazy loading

Scroll this section into view to load the detailed rows.

Publisher Evidence

Low

Codigrate

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

82
Noisy-finding weight
x1.00
Publisher domain
codigrate.com
Observed
Store verification signal
Verified publisher
Verified
Extension portfolio
52
Portfolio

12 evidence rows available.

Finding Categories

246
IoC Indicators

YARA Rules Matched

3 rules(82 hits)
postinstall persistence mechanism postinstall system command postinstall file manipulation

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality moderate.

All In One Themes is a color theme pack for JetBrains IDEs, published by Codigrate. Every medium-severity URL finding points at one host and follows one shape: codigrate.com/util/color/DCA225.png?width=18&height=18, codigrate.com/util/color/3B3A45.png?width=18&height=18, codigrate.com/util/color/F1F9F3.png?width=18&height=18, and roughly 240 more in the same form. Each path segment is a hex color and each URL carries an 18 by 18 size parameter. Those are swatch images behind a theme picker. Fetching preview chips from the publisher's own domain is what a theme plugin does, and the same pattern of finding appears under the publisher's color utility path in every case.

The scan found no file reads outside the plugin's own packaged resources, no process spawning and no shell execution. No malware signature matched, no credential store was read and no obfuscation was detected. There is no reference to .env, .ssh, .git/config or any cloud credential file anywhere in the finding set, which matters because a theme extension has no reason to open them. Theme JSON, font definitions and webview assets are the only files this class of plugin needs, and nothing here points past that.

The 82 low-severity code-smell items are the standard yield of pattern rules run over bundled JavaScript. The rules behind them match generic Node.js idioms such as fs, exec, fetch and process.env, and they fire on almost every extension with a compiled front end. They carry no weight on their own, and the same is true of the 85 informational items.

One entry deserves a mention. The endpoint list includes bash.here, which reads like a shell reference and would be alarming sitting next to a command execution path. It does not have one. No finding title, file path or process-spawning result is attached to it, and the rest of the network surface is the publisher's asset host plus plugins.jetbrains.com, the marketplace's own update endpoint. A bare string lifted from bundled code, with no caller, is not execution.

The strongest argument against calling this clean is volume. Two hundred forty-six address findings is a lot to see on one page, and the empty description field means there is no stated purpose to weigh the behavior against. Look at what the addresses are, though. They are one publisher's color assets requested at thumbnail size, repeated across a palette. The count tracks the number of swatches rather than the number of destinations. With no credential access, no filesystem reach and no execution path, nothing in this set rises above the plugin's stated job of drawing themes.

Key Reasons

  • All 246 URL findings resolve to codigrate.com/util/color/.png?width=18&height=18, the publisher's own color swatch assets for a theme picker
  • No credential-access findings: nothing references .env, .ssh, .git/config or cloud credential files
  • No filesystem, process-spawning, obfuscation or malware-signature findings accompany the URL hits
  • The 82 low-severity code-smell items match generic Node.js idioms (fs, exec, fetch, process.env) common to any bundled JavaScript
  • The bash.here endpoint string has no associated file path, finding title or execution result

False Positive Considerations

  • XIOC URL extraction counts each repeated color swatch URL as a separate medium-severity finding, inflating the total to 246
  • Generic code-smell YARA rules matching fs, exec, fetch and process.env patterns in bundled JavaScript
  • Bare hostname-like string (bash.here) lifted from minified code with no caller in the finding set
  • Empty description and permission fields offer no stated purpose to compare behavior against, so asset fetches read as unexplained network activity

Reviewed 2026-10-01; recommended action: suppress false positive; model confidence 82%.

JetBrains version history

Risk trend by version

12 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
47
Change since first
+4
Change from previous
No change
Versions:
First analyzed version
2026.1.9
Apr 19, 2026
Risk range
39 to 47
Across analyzed versions
Latest analyzed version
2026.1.23
Sep 29, 2026
Selected version
medium
Version
v2026.1.23
2 days ago
Risk score
47
Findings
413
Change vs previous
0

Pick any point on the chart to explore that version's code below.

About This Extension

24 carefully curated themes in one package! From calm pastel environments inspired by nature, seasons, and soft daylight to rich cinematic palettes shaped by iconic...

Frequently Asked Questions