Notepad++ Plugins

Columns++

bb5c148d-17cc-54ce-9ad2-b8107f83c3fb | v1.3.3
61/ 100
MEDIUM risk
+15 since v1.3.1
Analyst verdict
Review before use

The AI review rates the findings as likely false positive, but the risk score (61/100) still counts them.

Analysis record

Analysed
1 months ago
Version
v1.3.3
Artifact
SHA256 787…496
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

6 detail rows

Network Indicators

Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.

49 total
...

Network indicators are queued for lazy loading

Scroll this section into view to load the detailed rows.

Finding Categories

1
Obfuscation
49
IoC Indicators

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality moderate.

The Columns++ extension for Notepad++ provides text and data column manipulation features including elastic tabstops, column alignment, and numeric calculations. The security findings in this bundle are overwhelmingly false positives from automated extraction noise rather than indicators of malicious behavior.

Filesystem and Process Access Justification: The extension's stated purpose justifies any filesystem access needed for column manipulation. Notepad++ plugins legitimately read and write workspace files to perform their functions. The findings show no evidence of suspicious process execution or unjustified file access patterns. The 10 code-smell findings are low severity and represent normal C++ code patterns expected in a non-trivial codebase.

Credential Access Findings: There are zero credential-access findings in this bundle. The findings_summary shows "secret":0 and no findings targeting .env files, .git/config, SSH keys, or cloud credentials. This is consistent with a legitimate text manipulation tool that does not need access to sensitive configuration files.

IoC Finding Analysis: All 100 IoC findings are documentation URLs to legitimate reference sites, not malicious network destinations. The XIOC-URL-https://github.com/boostorg/regex/ finding points to the Boost C++ library documentation, a standard dependency for regex functionality. Similarly, XIOC-URL-https://www.boost.org/doc/libs/release/libs/regex/doc/html/boost_regex/syntax/perl_syntax.html#boost_regex.syntax.perl_syntax.collating_elements references Boost regex syntax documentation. The XIOC-URL-https://nlohmann.me finding references a popular JSON library. The XIOC-URL-https://en.wikipedia.org/wiki/Unicode and XIOC-URL-https://en.wikipedia.org/wiki/UTF-16 findings reference encoding documentation. These are not network destinations the extension calls - they are documentation strings extracted from comments or help text. The XIOC-URL-https://npp-user-manual.org/docs/searching/#extended-search-mode finding references Notepad++ official documentation.

Strongest Counterargument: The 0 user count is unusual for a published Notepad++ plugin. This could indicate a newly published extension, a re-upload, or a supply chain attempt. However, the nature of the findings (all documentation URLs) does not support malicious intent. A supply chain attack would show actual malware signatures or suspicious network calls to non-documentation domains, not documentation references. The findings_summary shows "malware-signature":"0" and "malware":"0", confirming no actual malicious code was detected.

Conclusion: The XIOC extractor flagged documentation URLs as IoCs, creating 100 false-positive findings. No malware signatures, credential theft patterns, or suspicious network behavior were detected. This is a legitimate text manipulation tool with noisy automated findings.

Key Reasons

  • All 100 IoC findings are documentation URLs, not malicious destinations
  • Zero malware signatures detected
  • Zero credential/secret access findings
  • Extension purpose justifies workspace file access
  • Code-smell findings are low severity and expected

False Positive Considerations

  • IoC extractor flagging documentation URLs as indicators
  • Code-smell findings on normal C++ patterns
  • Reference links to GitHub/Wikipedia/Boost.org in comments
  • No actual malware signatures or credential access findings

Reviewed 2026-04-27; recommended action: suppress false positive; model confidence 75%.

Notepad++ version history

Risk trend by version

2 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
61
Change since first
+15
Change from previous
+15
Versions:
First analyzed version
1.3.1
Apr 5, 2026
Risk range
46 to 61
Across analyzed versions
Latest analyzed version
1.3.3
Aug 10, 2026
Selected version
medium
Version
v1.3.3
1 months ago
Risk score
61
Findings
55
Change vs previous
+15

Pick any point on the chart to explore that version's code below.

Frequently Asked Questions