Notepad++ Plugins

Compose

a16e753c-1ecf-544a-9217-614d1388f7f6 | v1.1.1
60/ 100
MEDIUM risk
+16 since v1.1
Analyst verdict
Review before use

The AI review rates the findings as likely false positive, but the risk score (60/100) still counts them.

Analysis record

Analysed
1 months ago
Version
v1.1.1
Artifact
SHA256 54E…C12
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

8 detail rows

Network Indicators

Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.

24 total
...

Network indicators are queued for lazy loading

Scroll this section into view to load the detailed rows.

Finding Categories

1
Obfuscation
24
IoC Indicators

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality strong.

The Compose Notepad++ plugin implements a compose key feature for entering special characters, a legitimate text editing utility. The 59 IoC findings consist entirely of documentation URLs embedded in the plugin's source files and license headers. The XIOC-URL findings reference Wikipedia pages (https://en.wikipedia.org/wiki/Dead_key, https://en.wikipedia.org/wiki/Compose_key), Microsoft keyboard documentation (https://learn.microsoft.com/en-us/globalization/keyboards/kbdhe), and GitHub repositories (https://github.com/Coises/Compose-for-NotepadPlusPlus, https://github.com/notepad-plus-plus/notepad-plus-plus). These are informational references, not network calls to suspicious endpoints.

The XIOC-IP-::d finding is an IPv6 fragment pattern, a documented false positive from hex substrings in minified or binary files. The XIOC-DOMAIN-c.ax and XIOC-DOMAIN-i.creativecommons.org findings are URL fragments from license attribution text (Creative Commons licensing), not active network destinations. The license URLs (https://www.gnu.org/licenses/gpl.html, https://www.opensource.org/licenses/MIT) confirm this is open-source software.

No credential-access findings target actual secrets. The 12 code-smell findings are expected noise from standard code patterns. Zero malware-signature, zero obfuscation, and zero secret findings indicate no malicious code was detected. The plugin's filesystem access is justified by its stated purpose: a compose key plugin must read and modify text content in the editor.

The strongest counterargument is the user_count of 0, which could indicate a re-upload or unverified extension. However, the GitHub repository reference (https://github.com/Coises/Compose-for-NotepadPlusPlus) provides source code transparency, and the developer name (Randall Joseph Fellmy) matches the repository author. The 0 user count alone does not establish malicious intent when all other findings are benign documentation references.

The findings pattern matches known CVEQ false-positive drivers: IoC extractor garbage on documentation URLs, IPv6 fragment misclassification, and code-smell noise on legitimate code. No postinstall payload execution, credential theft, or exfiltration patterns are present.

Key Reasons

  • All IoC findings are documentation URLs, not malicious network destinations
  • Zero malware signatures, obfuscation, or secret findings detected
  • GitHub source repository provides code transparency
  • IPv6 fragment (::d) is known false positive pattern
  • Code-smell findings are expected noise on legitimate code

False Positive Considerations

  • IoC extractor matching documentation URLs as indicators
  • IPv6 fragment false positive (::d pattern)
  • Code-smell rules on legitimate code patterns
  • License file URLs flagged as network indicators

Reviewed 2026-04-27; recommended action: suppress false positive; model confidence 78%.

Notepad++ version history

Risk trend by version

2 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
60
Change since first
+16
Change from previous
+16
Versions:
First analyzed version
1.1
Apr 5, 2026
Risk range
45 to 60
Across analyzed versions
Latest analyzed version
1.1.1
Aug 10, 2026
Selected version
medium
Version
v1.1.1
1 months ago
Risk score
60
Findings
32
Change vs previous
+16

Pick any point on the chart to explore that version's code below.

Frequently Asked Questions