JetBrains Marketplace Verified

Etna Theme

by Codigrate · 44 users
cdcf34cd-b2f5-57e9-8384-9b038f6917ec | v2026.1.2
44/ 100
MEDIUM risk
No change since v2026.1.1
Analyst verdict
Review before use

The AI review rates the findings as likely false positive, but the risk score (44/100) still counts them.

Analysis record

Analysed
2 days ago
Version
v2026.1.2
Artifact
SHA256 1E9…368
Source
Findings (non-IoC)

Is Etna Theme safe?

Etna Theme is a visual theme for JetBrains IDEs made by Codigrate. It changes the colors and appearance of your editor. The extension declares no special permissions and requests no filesystem or network access beyond what a theme normally needs.

The scanner flagged 293 network indicators, but every single one points to codigrate.com, the publisher's own website. These are URLs for color swatch images like https://codigrate.com/util/color/E2BF79.png?width=18&height=18 that the theme uses to display its color palette. Other hits reference Inkscape SVG namespaces and the official JetBrains plugin page. The scanner also found 2 low-severity code pattern matches, which are standard noise that fires on any non-trivial code.

This is a false positive. The scanner tripped on the publisher's own asset URLs and standard SVG metadata. A theme extension that references its own color images and preview assets is doing exactly what it should. There are no malware signatures, no credential access, and no suspicious behavior. The extension is safe to install.

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

5 detail rows

Publisher Evidence

Low

Codigrate

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

82
Noisy-finding weight
x1.00
Publisher domain
codigrate.com
Observed
Store verification signal
Verified publisher
Verified
Extension portfolio
52
Portfolio

12 evidence rows available.

Finding Categories

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality strong.

The Etna Theme extension by Codigrate is a cosmetic theme for JetBrains IDEs. Theme extensions change the visual appearance of the editor through color schemes and UI styling. They have no legitimate need to access the filesystem, execute processes, or read source code. This extension declares no permissions in its manifest and requests no host permissions, which is appropriate for a theme.

The findings consist entirely of 293 IoC detections and 2 low-severity code-smell matches. Every IoC finding points to URLs on codigrate.com, the publisher's own domain. The detected URLs follow the pattern https://codigrate.com/util/color/[HEX].png?width=18&height=18, which are 18x18 pixel color swatch images used for theme preview rendering. Other IoC hits reference https://codigrate.com/tools/color/[HEX] paths and the official JetBrains plugin page at https://plugins.jetbrains.com/plugin/34642-dublin-theme. These are not suspicious network calls. They are static asset URLs that a theme extension would legitimately reference to display color palettes and preview images.

The network endpoints list includes sodipodi.sourceforge.net and www.inkscape.org, which are standard SVG namespace declarations found in vector graphics files. Theme packages often include SVG icons or assets created in Inkscape, and these namespaces are embedded in the SVG XML metadata. This is expected and benign. The plugins.jetbrains.com endpoint is the official marketplace URL.

The two code-smell findings are low-severity matches that fire on basic code patterns. These are explicitly documented as noise sources that match on non-trivial JavaScript but do not indicate malicious behavior.

The strongest counterargument to a benign verdict is the high volume of IoC findings (293 total). However, volume alone does not indicate risk. Every single IoC hit resolves to either the publisher's own domain serving theme assets, standard SVG namespace URLs, or the official JetBrains marketplace. There are zero malware signatures, zero credential-access findings, zero obfuscation detections, and zero evidence of postinstall execution or data exfiltration. The extension does exactly what a theme should do and nothing more.

Key Reasons

  • All 293 IoC findings point to publisher's own domain (codigrate.com) serving color swatch images
  • Network endpoints are standard SVG namespaces and official JetBrains marketplace
  • Zero malware signatures, zero credential access, zero obfuscation
  • Extension declares no permissions, appropriate for a theme
  • Code-smell findings are documented noise sources

False Positive Considerations

  • IoC hits on publisher's own domain serving theme assets
  • SVG namespace URLs from Inkscape/Sodipodi in theme graphics
  • Official JetBrains marketplace URL detection
  • Low-severity code-smell matches on standard patterns

Reviewed 2026-10-01; recommended action: suppress false positive; model confidence 92%.

JetBrains version history

Risk trend by version

3 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
44
Change since first
No change
Change from previous
No change
Versions:
First analyzed version
2026.1.0
Sep 16, 2026
Risk range
44 to 44
Across analyzed versions
Latest analyzed version
2026.1.2
Sep 29, 2026
Selected version
medium
Version
v2026.1.2
2 days ago
Risk score
44
Findings
300
Change vs previous
0

Pick any point on the chart to explore that version's code below.

About This Extension

Inspired by Mount Etna at night, where black basalt slopes fall away from a glowing crater and embers drift over the lava fields, this theme layers volcanic ash and...

Frequently Asked Questions