Based on the RiskyPlugins AI security review of the observed evidence.
No individual score drivers were recorded for this analysis.
Analysis record
- Analysed
- 7 months ago
- Version
- v2.9.0.1
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
Finding Categories
AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality moderate.
Filesystem/Process Access Justification
WebEdit is a Notepad++ plugin that expands code snippets from abbreviations. The extension's stated purpose—providing 1000+ preset tags for HTML, JavaScript, CSS, PHP, and SQL—requires reading template files and inserting text into the editor. This is standard behavior for a code snippet tool and does not require elevated filesystem or process access. The evidence bundle contains zero manifest-analysis findings, zero network findings, and zero code-smell findings, which means there is no evidence of suspicious file access patterns, process spawning, or data exfiltration behavior.
Credential Access Findings
The findings bundle shows zero secret findings and zero credential-related code-smell findings. The IoC findings that might appear credential-related are all XIOC extraction artifacts: XIOC-DOMAIN-system.gc.name and XIOC-DOMAIN-system.int are property access chains misread as domains (e.g., system.gc.name is likely system.gc.name object property access in code). The XIOC-DOMAIN-aka.ms finding is a Microsoft shortener domain used legitimately in documentation. None of these findings target .env files, .git/config, SSH keys, or cloud credentials.
Strongest Counterargument
The strongest counterargument is that Notepad++ plugins are native DLLs, and findings in native binaries carry more weight than JavaScript extension findings. However, this argument fails because the findings are exclusively IoC detections from the XIOC extractor, which is documented as producing massive false-positive volumes. There are zero malware-signature findings, zero malware findings, zero obfuscation findings, and zero code-smell findings across all 99 total findings. The 37 medium-severity IoC findings consist entirely of: IPv6 fragments (db::, f::, ::), loopback IP ranges (4.0.0.0), property access chains (system.gc.name, system.int), and benign infrastructure domains (aka.ms). None of these indicate actual malicious behavior.
The extension has zero user count, but this reflects a new or niche plugin rather than malicious intent. Without malware signatures, behavioral indicators, or evidence of capability beyond stated purpose, the verdict remains likely_false_positive.
Key Reasons
- Zero malware signatures or behavioral indicators
- All IoC findings match documented XIOC false positive patterns
- No code-smell or obfuscation findings
- Extension purpose aligns with required capabilities
False Positive Considerations
- XIOC IPv6 fragment extraction (db::, f::, ::)
- Property access chains misidentified as domains (system.gc.name)
- Benign infrastructure domains (aka.ms)
- Loopback/private IP ranges (4.0.0.0)
Reviewed 2026-04-27; recommended action: suppress false positive; model confidence 85%.
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace