Notepad++ Plugins

Pork to Sausage

by Don HO
e667c7e9-9b54-5823-a3da-284439724a2c | v2.6
36/ 100
LOW risk
Analyst verdict
No high-risk signal observed

Based on the RiskyPlugins AI security review of the observed evidence.

Analysis record

Analysed
7 months ago
Version
v2.6
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

16 detail rows

YARA Rule Matches

2 rules
SeverityRuleHitsFilesMetadata
HIGHpostinstall system command

System command execution detected

3
Config/pork2Sausage.inilicense.txtdemo/zip.base64/zipB64.java
Risky Plugins Authors FP 10%
HIGHpostinstall obfuscation

Code obfuscation techniques detected

5
Config/pork2Sausage.inireadme.txtdemo/zip.base64/readme.txt +2 more
Risky Plugins Authors FP 20%

Finding Categories

8
Malware Signatures

YARA Rules Matched

2 rules(8 hits)
postinstall system command postinstall obfuscation

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality moderate.

Security Analysis: Pork to Sausage Notepad++ Plugin

Filesystem and Process Access Assessment

The extension "Pork to Sausage" is a Notepad++ plugin with the stated purpose of passing selected text to command line programs and replacing the selection with program output. This functionality legitimately requires process spawning capabilities. The evidence bundle contains 8 code-smell findings, which are expected noise from YARA code-quality rules that match basic programming patterns. There are no findings indicating unauthorized filesystem access, credential theft, or process execution beyond the extension's documented scope. The plugin's process access is justified by its core functionality of executing external commands on user-selected text.

Credential Access Assessment

The evidence bundle contains zero secret findings and zero credential-related findings. The IOC findings include developer contact emails ([email protected] at file path extracted_from_files, [email protected] at file path extracted_from_files) and free email provider domains (free.fr, altern.org). These are legitimate contact information for the developer Don HO, not credential theft indicators. There are no findings targeting .env files, .git/config, SSH keys, or cloud credentials.

IOC Finding Analysis

All 13 IOC findings are false positives from the XIOC extractor, matching documented noise patterns. The findings include IPv6 fragments (::, e::fa, e::badb, e::e) which are hex substrings from minified code, not real IP addresses. Property access chains misread as domains (inflater.read, java.io, java.util.zip) are Java package references. Developer emails are legitimate contact information. The XIOC extractor is known to produce massive false-positive volumes, and these specific findings match documented noise patterns.

Strongest Counterargument

The strongest argument against this verdict would be the total finding count of 29 findings with 13 marked as "medium" severity IOC findings. However, finding count alone is meaningless according to CVEQ's known false-positive patterns. The XIOC extractor produces massive false-positive volumes, and these specific findings match documented noise patterns (IPv6 fragments, property chains, developer emails). No malware signatures, network findings, obfuscation findings, or secret findings exist in this bundle. The code-smell findings are classified as low severity and should never drive a verdict per the guidelines.

Conclusion

This is a legitimate Notepad++ plugin with standard utility functionality. All findings are from known false-positive patterns in the CVEQ analysis pipeline. The extension's purpose is clear and justified, with no evidence of malicious behavior. The developer Don HO is a known software developer, and the extension has zero user count which is typical for niche Notepad++ plugins.

Key Reasons

  • All 13 IOC findings are XIOC extractor false positives (IPv6 fragments, property chains, developer emails)
  • Zero malware signatures, network findings, or secret findings in the evidence bundle
  • Extension purpose (command execution on selected text) justifies process spawning capabilities
  • Code-smell findings are expected noise from YARA rules on basic programming patterns

False Positive Considerations

  • XIOC-IP-IPv6 fragments (::, e::fa, e::badb, e::e)
  • XIOC-DOMAIN property access chains (java.io, java.util.zip, inflater.read)
  • Developer contact emails ([email protected], [email protected])
  • Code-smell YARA rules on basic programming patterns

Reviewed 2026-04-27; recommended action: suppress false positive; model confidence 85%.

Frequently Asked Questions