Notepad++ Plugins

WebEdit

77b444b3-27b2-510f-8ad5-b9aa6c05cd78 | v2.9.0.1
21/ 100
LOW risk
Analyst verdict
No high-risk signal observed

Based on the RiskyPlugins AI security review of the observed evidence.

No individual score drivers were recorded for this analysis.

Analysis record

Analysed
7 months ago
Version
v2.9.0.1
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

62 detail rows
Showing 25 of 62 · highest severity first

Finding Categories

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality moderate.

Filesystem/Process Access Justification

WebEdit is a Notepad++ plugin that expands code snippets from abbreviations. The extension's stated purpose—providing 1000+ preset tags for HTML, JavaScript, CSS, PHP, and SQL—requires reading template files and inserting text into the editor. This is standard behavior for a code snippet tool and does not require elevated filesystem or process access. The evidence bundle contains zero manifest-analysis findings, zero network findings, and zero code-smell findings, which means there is no evidence of suspicious file access patterns, process spawning, or data exfiltration behavior.

Credential Access Findings

The findings bundle shows zero secret findings and zero credential-related code-smell findings. The IoC findings that might appear credential-related are all XIOC extraction artifacts: XIOC-DOMAIN-system.gc.name and XIOC-DOMAIN-system.int are property access chains misread as domains (e.g., system.gc.name is likely system.gc.name object property access in code). The XIOC-DOMAIN-aka.ms finding is a Microsoft shortener domain used legitimately in documentation. None of these findings target .env files, .git/config, SSH keys, or cloud credentials.

Strongest Counterargument

The strongest counterargument is that Notepad++ plugins are native DLLs, and findings in native binaries carry more weight than JavaScript extension findings. However, this argument fails because the findings are exclusively IoC detections from the XIOC extractor, which is documented as producing massive false-positive volumes. There are zero malware-signature findings, zero malware findings, zero obfuscation findings, and zero code-smell findings across all 99 total findings. The 37 medium-severity IoC findings consist entirely of: IPv6 fragments (db::, f::, ::), loopback IP ranges (4.0.0.0), property access chains (system.gc.name, system.int), and benign infrastructure domains (aka.ms). None of these indicate actual malicious behavior.

The extension has zero user count, but this reflects a new or niche plugin rather than malicious intent. Without malware signatures, behavioral indicators, or evidence of capability beyond stated purpose, the verdict remains likely_false_positive.

Key Reasons

  • Zero malware signatures or behavioral indicators
  • All IoC findings match documented XIOC false positive patterns
  • No code-smell or obfuscation findings
  • Extension purpose aligns with required capabilities

False Positive Considerations

  • XIOC IPv6 fragment extraction (db::, f::, ::)
  • Property access chains misidentified as domains (system.gc.name)
  • Benign infrastructure domains (aka.ms)
  • Loopback/private IP ranges (4.0.0.0)

Reviewed 2026-04-27; recommended action: suppress false positive; model confidence 85%.

Frequently Asked Questions