JetBrains Marketplace Verified

Madrid Theme

by Codigrate · 34 users
da56802c-f369-5175-8fad-daa43286492b | v2026.1.2
44/ 100
MEDIUM risk
No change since v2026.1.1
Analyst verdict
Review before use

The AI review rates the findings as likely false positive, but the risk score (44/100) still counts them.

Analysis record

Analysed
2 days ago
Version
v2026.1.2
Artifact
SHA256 3CD…840
Source
Findings (non-IoC)

Is Madrid Theme safe?

Madrid Theme is a color scheme for JetBrains editors published by Codigrate. It declares no special permissions and requests no host access. The only network endpoints referenced in the package are codigrate.com and plugins.jetbrains.com.

The scanner flagged 290 network indicators. That number sounds alarming until you look at what the links actually are. Every single indicator is a URL pointing to a tiny color swatch image on the developer's own website. One specific finding, titled XIOC-URL-https://codigrate.com/util/color/4F303C.png?width=18&height=18, just fetches a small preview of a dark purple shade. If these were real exfiltration channels, they would route to unknown infrastructure. Instead, they route to static image files.

The automated tool tripped on the sheer volume of picture links embedded in the theme metadata. A color theme needs to show users what its palette looks like. The author included dozens of preview images to help with that choice. The scanner counted every single picture link as a separate network event and raised an alert based on the total. There are zero malware signatures in the code, no credential access attempts, and no hidden script execution. The extension simply changes how your editor looks.

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

5 detail rows

Publisher Evidence

Low

Codigrate

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

82
Noisy-finding weight
x1.00
Publisher domain
codigrate.com
Observed
Store verification signal
Verified publisher
Verified
Extension portfolio
52
Portfolio

12 evidence rows available.

Finding Categories

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality strong.

The Madrid Theme extension for JetBrains IDEs, published by Codigrate, is a visual color scheme. It declares no special permissions in its manifest and requests no host access. Because it is purely a theme, it has no legitimate need for filesystem or process execution capabilities. The evidence confirms this absence. There are zero findings related to process spawning, file system reads, or workspace manipulation. The workspace access risk is effectively none. A theme only needs to register color definitions with the editor's rendering engine.

Credential access is entirely absent from this package. The findings summary shows zero secret detections and zero credential-related code smells. The extension does not attempt to read .env files, SSH keys, or cloud configurations. It does not interact with the IDE's secret storage. This is exactly what we expect from a theme that only modifies syntax highlighting and UI colors. It has no reason to look at your project files or your environment variables.

The bulk of the scanner output consists of 290 medium-severity indicators of compromise. Every single one of these findings is a URL extracted from the extension's metadata or documentation. The titles follow a strict pattern, such as XIOC-URL-https://codigrate.com/util/color/4F303C.png?width=18&height=18 and XIOC-URL-https://codigrate.com/util/color/DDBE6D.png?width=18&height=18. These URLs point to the developer's own domain, codigrate.com, and request tiny PNG images representing specific hex color codes. Another finding points to https://plugins.jetbrains.com/plugin/34642-dublin-theme, which is simply a link to another theme by the same author. These are static assets for a color palette preview, not dynamic network callbacks. The extension fetches a small picture of a color so the marketplace page can display it.

The strongest counterargument to clearing this extension is the sheer volume of network indicators. A count of 290 flagged URLs looks like beaconing or data exfiltration at first glance. An analyst might worry that the extension is phoning home repeatedly. However, the nature of the destinations completely undermines that concern. The URLs do not point to unknown infrastructure, tracking pixels, or data collection endpoints. They point to a predictable path on the publisher's own website serving static image files. The XIOC extractor flagged every individual image link as a separate event, inflating the total count through multiplicative false positives. When you look at the actual destinations, the alarm disappears.

There are zero malware signatures, zero obfuscation findings, and zero tool-poisoning indicators in the bundle. The two low-severity code-smell findings are standard noise from basic JavaScript patterns and do not represent actual malicious logic. The extension does exactly what its name implies. It changes the editor's color scheme and provides preview images to help users decide if they like it.

Key Reasons

  • All 290 IoC findings are static color swatch URLs on the publisher's own domain
  • Zero malware signatures, zero obfuscation, and zero secret detections
  • Extension declares no special permissions or host access
  • High finding count is purely a multiplicative false positive from the XIOC extractor counting individual image links

False Positive Considerations

  • XIOC extractor flagging every static image URL in metadata as a separate network indicator
  • Code-smell rules firing on basic theme JavaScript

Reviewed 2026-10-01; recommended action: suppress false positive; model confidence 95%.

JetBrains version history

Risk trend by version

3 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
44
Change since first
No change
Change from previous
No change
Versions:
First analyzed version
2026.1.0
Sep 16, 2026
Risk range
44 to 44
Across analyzed versions
Latest analyzed version
2026.1.2
Sep 29, 2026
Selected version
medium
Version
v2026.1.2
2 days ago
Risk score
44
Findings
297
Change vs previous
0

Pick any point on the chart to explore that version's code below.

About This Extension

Inspired by a Madrid balcony at midday, from sunlit facades and saffron awnings to the claveles spilling over the railings, this theme pairs warm golden and cream...

Frequently Asked Questions