Sydney Theme
The AI review rates the findings as likely false positive, but the risk score (44/100) still counts them.
Analysis record
- Analysed
- 2 days ago
- Version
- v2026.1.2
- Artifact
- SHA256 E77…6A0
- Source
- Findings (non-IoC)
Is Sydney Theme safe?
The Sydney Theme extension by Codigrate is a color scheme for JetBrains IDEs. It changes how your editor looks. The extension declares no special permissions and no host permissions, meaning it cannot access files outside its visual customization scope or make arbitrary network requests.
The security scan flagged 290 network indicators under titles like XIOC-URL-https://codigrate.com/util/color/82D59F.png, but every single one is a URL to either the developer's own website or the official JetBrains marketplace. These findings serve small color preview images that display the theme's palette in the marketplace listing. The plugins.jetbrains.com URLs link to official JetBrains documentation. If any of these were pointing to unknown servers or analytics trackers, that would be worth investigating. They are not.
The scan found zero malware signatures, zero obfuscation, and zero credential-access patterns. The two low-severity code-smell findings are routine matches that fire on ordinary code and do not indicate malicious behavior.
The high finding count comes from the scanner flagging every color swatch URL as a separate network indicator. A theme with 50 colors generates 50 URL findings, even though all 50 point to the developer's own image server. This is a known limitation of automated URL extraction. The extension is doing nothing wrong.
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
Publisher Evidence
LowCodigrate
Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
12 evidence rows available.
Finding Categories
AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality strong.
The Sydney Theme extension by Codigrate is a JetBrains IDE theme. Themes are visual customization packages that change the color scheme of the editor interface. They have no reason to read source files, execute processes, or access credentials.
The extension declares no permissions and no host permissions. The permissions and host_permissions arrays are both empty. This means the extension operates entirely within the visual customization scope that JetBrains allows for themes.
The 290 IoC findings are all URLs. Examining the specific findings reveals they fall into two categories. The first is https://codigrate.com/util/color/*.png?width=18&height=18 URLs, which serve small color swatch images from the developer's own website. These are standard assets for theme preview pages in JetBrains marketplace listings. The second category includes https://plugins.jetbrains.com/plugin/34273-fuji-theme and https://plugins.jetbrains.com/docs/marketplace/plugin-overview-page.html#plugin-name, which are official JetBrains marketplace URLs. None of these URLs point to external analytics services, command-and-control infrastructure, or data exfiltration endpoints.
The two code-smell findings at low severity are not specified in detail, but code-smell classifications are documented noise sources that fire on routine code patterns. They do not indicate malicious behavior.
Zero malware signatures matched. Zero obfuscation findings. Zero secret-detection findings. Zero tool-poisoning indicators. The extension contains no evidence of postinstall payload execution, credential theft, or source code exfiltration.
The extension has 34 users and is at version 2026.1.2. The low user count is typical for niche theme extensions on the JetBrains marketplace, where thousands of themes compete for attention. It raises no supply-chain concerns. The version number follows JetBrains' date-based versioning scheme.
The strongest counterargument to a benign verdict is the sheer volume of IoC findings: 290 medium-severity detections. A reader might wonder why a simple theme generates so many network indicators. The answer is that the IoC extractor flags every URL it encounters, including the dozens of color swatch images a theme needs to display its palette. Each hex color code in the theme becomes a separate URL request to codigrate.com/util/color/, and each one triggers a finding. This is multiplicative false positive generation. It does not reflect suspicious network activity.
The extension's network endpoints are codigrate.com (the developer's own domain) and plugins.jetbrains.com (the official JetBrains marketplace). Both are expected for a theme that fetches its own preview assets and links to marketplace documentation.
This extension is a standard JetBrains theme with no malicious indicators. The findings are entirely explained by the IoC extractor flagging every URL, including benign color swatch images and official marketplace links.
Key Reasons
- All 290 IoC findings are URLs to the developer's own color swatch images (codigrate.com/util/color/*.png) or official JetBrains marketplace pages
- Extension declares no permissions and no host permissions
- Zero malware signatures, zero obfuscation, zero secret-detection findings
- Theme extensions have no legitimate reason to access credentials or execute processes, and this one does neither
False Positive Considerations
- IoC extractor flags every URL including benign color swatch images from the developer's own site
- Code-smell findings fire on routine patterns in theme configuration code
- High finding count driven by multiplicative URL extraction from theme color palette
Reviewed 2026-10-01; recommended action: suppress false positive; model confidence 95%.
JetBrains version history
Risk trend by version
3 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace