The AI review rates the findings as likely false positive, but the risk score (61/100) still counts them.
Analysis record
- Analysed
- 1 months ago
- Version
- v1.3.3
- Artifact
- SHA256 787…496
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
Network Indicators
Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.
Network indicators are queued for lazy loading
Scroll this section into view to load the detailed rows.
Finding Categories
AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality moderate.
The Columns++ extension for Notepad++ provides text and data column manipulation features including elastic tabstops, column alignment, and numeric calculations. The security findings in this bundle are overwhelmingly false positives from automated extraction noise rather than indicators of malicious behavior.
Filesystem and Process Access Justification: The extension's stated purpose justifies any filesystem access needed for column manipulation. Notepad++ plugins legitimately read and write workspace files to perform their functions. The findings show no evidence of suspicious process execution or unjustified file access patterns. The 10 code-smell findings are low severity and represent normal C++ code patterns expected in a non-trivial codebase.
Credential Access Findings: There are zero credential-access findings in this bundle. The findings_summary shows "secret":0 and no findings targeting .env files, .git/config, SSH keys, or cloud credentials. This is consistent with a legitimate text manipulation tool that does not need access to sensitive configuration files.
IoC Finding Analysis: All 100 IoC findings are documentation URLs to legitimate reference sites, not malicious network destinations. The XIOC-URL-https://github.com/boostorg/regex/ finding points to the Boost C++ library documentation, a standard dependency for regex functionality. Similarly, XIOC-URL-https://www.boost.org/doc/libs/release/libs/regex/doc/html/boost_regex/syntax/perl_syntax.html#boost_regex.syntax.perl_syntax.collating_elements references Boost regex syntax documentation. The XIOC-URL-https://nlohmann.me finding references a popular JSON library. The XIOC-URL-https://en.wikipedia.org/wiki/Unicode and XIOC-URL-https://en.wikipedia.org/wiki/UTF-16 findings reference encoding documentation. These are not network destinations the extension calls - they are documentation strings extracted from comments or help text. The XIOC-URL-https://npp-user-manual.org/docs/searching/#extended-search-mode finding references Notepad++ official documentation.
Strongest Counterargument: The 0 user count is unusual for a published Notepad++ plugin. This could indicate a newly published extension, a re-upload, or a supply chain attempt. However, the nature of the findings (all documentation URLs) does not support malicious intent. A supply chain attack would show actual malware signatures or suspicious network calls to non-documentation domains, not documentation references. The findings_summary shows "malware-signature":"0" and "malware":"0", confirming no actual malicious code was detected.
Conclusion: The XIOC extractor flagged documentation URLs as IoCs, creating 100 false-positive findings. No malware signatures, credential theft patterns, or suspicious network behavior were detected. This is a legitimate text manipulation tool with noisy automated findings.
Key Reasons
- All 100 IoC findings are documentation URLs, not malicious destinations
- Zero malware signatures detected
- Zero credential/secret access findings
- Extension purpose justifies workspace file access
- Code-smell findings are low severity and expected
False Positive Considerations
- IoC extractor flagging documentation URLs as indicators
- Code-smell findings on normal C++ patterns
- Reference links to GitHub/Wikipedia/Boost.org in comments
- No actual malware signatures or credential access findings
Reviewed 2026-04-27; recommended action: suppress false positive; model confidence 75%.
Notepad++ version history
Risk trend by version
2 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace