Madrid Theme
The AI review rates the findings as likely false positive, but the risk score (44/100) still counts them.
Analysis record
- Analysed
- 2 days ago
- Version
- v2026.1.2
- Artifact
- SHA256 3CD…840
- Source
- Findings (non-IoC)
Is Madrid Theme safe?
Madrid Theme is a color scheme for JetBrains editors published by Codigrate. It declares no special permissions and requests no host access. The only network endpoints referenced in the package are codigrate.com and plugins.jetbrains.com.
The scanner flagged 290 network indicators. That number sounds alarming until you look at what the links actually are. Every single indicator is a URL pointing to a tiny color swatch image on the developer's own website. One specific finding, titled XIOC-URL-https://codigrate.com/util/color/4F303C.png?width=18&height=18, just fetches a small preview of a dark purple shade. If these were real exfiltration channels, they would route to unknown infrastructure. Instead, they route to static image files.
The automated tool tripped on the sheer volume of picture links embedded in the theme metadata. A color theme needs to show users what its palette looks like. The author included dozens of preview images to help with that choice. The scanner counted every single picture link as a separate network event and raised an alert based on the total. There are zero malware signatures in the code, no credential access attempts, and no hidden script execution. The extension simply changes how your editor looks.
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
Publisher Evidence
LowCodigrate
Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
12 evidence rows available.
Finding Categories
AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality strong.
The Madrid Theme extension for JetBrains IDEs, published by Codigrate, is a visual color scheme. It declares no special permissions in its manifest and requests no host access. Because it is purely a theme, it has no legitimate need for filesystem or process execution capabilities. The evidence confirms this absence. There are zero findings related to process spawning, file system reads, or workspace manipulation. The workspace access risk is effectively none. A theme only needs to register color definitions with the editor's rendering engine.
Credential access is entirely absent from this package. The findings summary shows zero secret detections and zero credential-related code smells. The extension does not attempt to read .env files, SSH keys, or cloud configurations. It does not interact with the IDE's secret storage. This is exactly what we expect from a theme that only modifies syntax highlighting and UI colors. It has no reason to look at your project files or your environment variables.
The bulk of the scanner output consists of 290 medium-severity indicators of compromise. Every single one of these findings is a URL extracted from the extension's metadata or documentation. The titles follow a strict pattern, such as XIOC-URL-https://codigrate.com/util/color/4F303C.png?width=18&height=18 and XIOC-URL-https://codigrate.com/util/color/DDBE6D.png?width=18&height=18. These URLs point to the developer's own domain, codigrate.com, and request tiny PNG images representing specific hex color codes. Another finding points to https://plugins.jetbrains.com/plugin/34642-dublin-theme, which is simply a link to another theme by the same author. These are static assets for a color palette preview, not dynamic network callbacks. The extension fetches a small picture of a color so the marketplace page can display it.
The strongest counterargument to clearing this extension is the sheer volume of network indicators. A count of 290 flagged URLs looks like beaconing or data exfiltration at first glance. An analyst might worry that the extension is phoning home repeatedly. However, the nature of the destinations completely undermines that concern. The URLs do not point to unknown infrastructure, tracking pixels, or data collection endpoints. They point to a predictable path on the publisher's own website serving static image files. The XIOC extractor flagged every individual image link as a separate event, inflating the total count through multiplicative false positives. When you look at the actual destinations, the alarm disappears.
There are zero malware signatures, zero obfuscation findings, and zero tool-poisoning indicators in the bundle. The two low-severity code-smell findings are standard noise from basic JavaScript patterns and do not represent actual malicious logic. The extension does exactly what its name implies. It changes the editor's color scheme and provides preview images to help users decide if they like it.
Key Reasons
- All 290 IoC findings are static color swatch URLs on the publisher's own domain
- Zero malware signatures, zero obfuscation, and zero secret detections
- Extension declares no special permissions or host access
- High finding count is purely a multiplicative false positive from the XIOC extractor counting individual image links
False Positive Considerations
- XIOC extractor flagging every static image URL in metadata as a separate network indicator
- Code-smell rules firing on basic theme JavaScript
Reviewed 2026-10-01; recommended action: suppress false positive; model confidence 95%.
JetBrains version history
Risk trend by version
3 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace