London Theme
The AI review rates the findings as likely false positive, but the risk score (44/100) still counts them.
Analysis record
- Analysed
- 2 days ago
- Version
- v2026.1.2
- Artifact
- SHA256 15B…CC3
- Source
- Findings (non-IoC)
Is London Theme safe?
London Theme is a color theme for JetBrains IDEs published by Codigrate. The extension declares no special permissions in its manifest, which means it cannot access your files, execute commands, or read credentials from your development environment. Theme extensions only need to define colors and styling, and this extension stays within that scope. The network endpoints listed in the analysis include codigrate.com (the publisher's own domain), plugins.jetbrains.com (the official JetBrains marketplace), and www.corel.com (likely from bundled assets). None of these are suspicious external services.
The analysis detected 292 indicators of compromise, but examining the specific findings shows they are all URLs to color preview images hosted on the publisher's own domain at paths like https://codigrate.com/util/color/0F91C7.png. These are legitimate theme preview assets, not malicious indicators. The findings also include links to other themes on the JetBrains marketplace. If these URLs were actually malicious, it would mean the publisher was using their own domain to serve harmful content, but there is no evidence of that. Zero malware signatures matched the extension code, and no credential-access findings were detected.
The verdict follows because the extension does what a theme should do and nothing more. The scanner tripped on the publisher's own domain URLs and official marketplace links, flagging them as indicators when they are actually expected content for a theme extension's metadata. With no permissions declared, no malicious code detected, and all findings pointing to the publisher's own infrastructure or official marketplace pages, there is no evidence this extension poses a security risk.
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
Publisher Evidence
LowCodigrate
Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
12 evidence rows available.
Finding Categories
AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality moderate.
Filesystem and Process Access
The London Theme extension declares zero permissions in its manifest. The host_permissions array is empty, and the permissions array is empty. This is appropriate for a theme extension, which only needs to define color values and UI styling. Theme extensions have no legitimate reason to read workspace files, execute processes, or access credentials. The absence of any declared permissions means the extension cannot perform filesystem operations, spawn child processes, or access sensitive developer environment files like .env, .ssh/config, or cloud credential stores.
Credential Access Findings
There are zero credential-access findings in this bundle. The secret category shows zero matches. No findings reference .env files, SSH keys, git credentials, or VS Code secret storage. The extension has no mechanism to read, store, or transmit credentials because it declares no permissions that would grant such access.
Analysis of Detected Indicators
The bundle contains 292 IoC findings, all classified as medium severity. Examining the specific findings reveals they are exclusively URLs pointing to https://codigrate.com/util/color/XXXXXX.png?width=18&height=18 (where XXXXXX is a hex color code), https://plugins.jetbrains.com/plugin/22826-sequoia-theme, and http://www.corel.com/coreldraw/odm/2003. These are not indicators of compromise. The codigrate.com URLs are the publisher's own domain serving color swatch preview images for the theme. The plugins.jetbrains.com URL is a link to another theme on the official JetBrains marketplace. The corel.com URL is likely from bundled metadata or third-party assets. None of these endpoints represent command-and-control infrastructure, data exfiltration targets, or suspicious third-party services.
The two code-smell findings are classified as low severity. Per standard analysis methodology, code-smell findings on theme configuration files are expected noise and do not indicate malicious behavior.
Strongest Counterargument
The strongest counterargument is that the extension has 292 detected indicators, which seems like a high volume. However, finding count alone is meaningless without examining the nature of those findings. All 292 IoC findings are URLs to the publisher's own color preview images and official marketplace links. A theme extension's metadata will naturally contain URLs to preview assets and related themes. The IoC extractor flagged these benign URLs as indicators, creating artificial volume. Zero findings indicate actual malicious behavior: no malware signatures matched, no credential access was detected, no obfuscation was found, and no suspicious network endpoints were identified.
Conclusion
This is a theme extension with no permissions, no malicious behavior, and findings that consist entirely of the publisher's own domain URLs and official marketplace links. The extension does exactly what a theme should do and nothing more.
Key Reasons
- Theme extension declares zero permissions in manifest
- All 292 IoC findings are URLs to publisher's own color preview images on codigrate.com
- Zero malware signatures, zero credential access, zero obfuscation detected
- Network endpoints limited to publisher domain and official JetBrains marketplace
- Code-smell findings are low-severity noise on theme configuration
False Positive Considerations
- IoC extractor flagging publisher's own domain URLs (codigrate.com color preview images)
- IoC extractor flagging official JetBrains marketplace URLs
- Code-smell rules firing on theme configuration files
- High finding count from bundled metadata and preview asset URLs
Reviewed 2026-10-01; recommended action: suppress false positive; model confidence 92%.
JetBrains version history
Risk trend by version
3 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace