OpenVSX Registry Verified

GTK CSS

8f54dc30-4f6c-5aff-9eb6-d3b224878c5b | v1.5.0
31/ 100
LOW risk
No change since v1.4.1
Analyst verdict
No high-risk signal observed

Based on the RiskyPlugins AI security review of the observed evidence.

Analysis record

Analysed
6 months ago
Version
v1.5.0
Artifact
SHA256 A8D…DF8
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

5 detail rows

Publisher Evidence

Low

mpmischitelli

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

55
Noisy-finding weight
x1.00
Publisher domain
No domain
Missing
Store verification signal
Verified publisher
Verified
Extension portfolio
2
Portfolio

12 evidence rows available.

Finding Categories

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality strong.

The GTK CSS extension provides syntax highlighting and IntelliSense for GTK-specific CSS properties. All 1223 IoC findings are documentation URLs from developer.mozilla.org/docs/Web/CSS/Reference/Properties/ (e.g., XIOC-URL-https://developer.mozilla.org/docs/Web/CSS/Reference/Properties/corner-end-end-shape). These URLs are documentation references embedded in the extension's code, likely in tooltips or comments, not network calls. The XIOC extractor incorrectly flags these benign documentation links as indicators of compromise.

The extension has zero malware-signature findings, zero malware findings, zero network findings, and zero secret findings. The 28 code-smell findings (severity=low) are expected in any non-trivial JavaScript extension and match the known false-positive pattern for code-smell rules that fire on basic Node.js patterns. The 5 dependency findings represent legitimate npm packages bundled with the extension.

Filesystem access for a CSS syntax highlighting extension is justified by its stated purpose. The extension reads CSS files to provide IntelliSense and syntax highlighting. There are no credential-access findings targeting .env files, .ssh directories, cloud credentials, or VS Code secret storage. The findings_summary shows "secret":0, confirming no credential theft patterns.

The strongest counterargument is the high finding count (1256 total). However, finding count is explicitly documented as noise in the CVEQ system. The nature of these findings reveals they are MDN documentation URLs, not malicious domains. A CSS documentation extension legitimately references CSS property documentation. The absence of any actual network, malware, or secret-access findings confirms this is not malicious behavior.

This extension exhibits the classic false-positive pattern: XIOC URL extraction on documentation links, code-smell findings from normal JavaScript, and no evidence of malicious intent or capability.

Key Reasons

  • All IoC findings are MDN documentation URLs, not malicious domains
  • Zero malware, network, or secret-access findings
  • Extension purpose (CSS syntax highlighting) justifies file read access
  • Code-smell findings are low-severity and expected

False Positive Considerations

  • XIOC URL extraction on MDN documentation links
  • Code-smell findings from normal JavaScript patterns
  • High finding count from documentation references
  • No actual network or malware findings

Reviewed 2026-04-27; recommended action: suppress false positive; model confidence 85%.

Open VSX version history

Risk trend by version

3 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
31
Change since first
No change
Change from previous
No change
Versions:
First analyzed version
1.2.0
Mar 15, 2026
Risk range
31 to 31
Across analyzed versions
Latest analyzed version
1.5.0
Apr 18, 2026
Selected version
low
Version
v1.5.0
5 months ago
Risk score
31
Findings
5
Change vs previous
No change

Pick any point on the chart to explore that version's code below.

About This Extension

Syntax highlighting and IntelliSense for GTK-specific CSS: @define-color, color functions (alpha, shade, mix), -gtk- properties, and GTK widget element selectors.

Frequently Asked Questions