Prague Theme
The AI review rates the findings as likely false positive, but the risk score (44/100) still counts them.
Analysis record
- Analysed
- 2 days ago
- Version
- v2026.1.2
- Artifact
- SHA256 5E5…B07
- Source
- Findings (non-IoC)
Is Prague Theme safe?
The Prague Theme is a visual theme for JetBrains IDEs published by Codigrate. It changes the colors and appearance of your editor. The extension declares no special permissions and requests no host-level access. The network endpoints it communicates with are limited to codigrate.com, which hosts the theme's assets, and plugins.jetbrains.com, the official marketplace.
The scanner flagged 291 network indicators, which sounds alarming at first glance. In reality, every single one of these alerts is just a URL pointing to a color swatch image on the publisher's own website, such as the codigrate.com/util/color directory. If these were real threats, they would represent the extension sending your data to a remote server, but they are actually just static pictures of the color palette used in the theme's documentation.
The high number of alerts is an artifact of how the scanner extracts URLs from the extension's metadata. It saw a long list of image links and flagged them as external network calls. There are no malware signatures, no attempts to read your private files or credentials, and no hidden code execution. The extension is a standard UI theme doing exactly what it was built to do.
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
Publisher Evidence
LowCodigrate
Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
12 evidence rows available.
Finding Categories
AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality strong.
The Prague Theme extension for JetBrains IDEs, published by Codigrate, is a visual theme package. An analysis of the extracted evidence shows no indicators of malicious behavior, credential theft, or unauthorized data collection. The extension declares no special permissions and requests no host-level access, which aligns perfectly with the expected behavior of a UI theme that only modifies editor colors and fonts.
The bulk of the scanner's findings consist of 291 indicators of compromise, all categorized as medium severity. A review of these alerts reveals they are exclusively URLs pointing to https://codigrate.com/util/color/[HEX].png with width and height parameters. These are clearly color swatch images hosted on the publisher's own domain, likely embedded in the extension's documentation or settings UI to display the theme's palette. The XIOC extractor flagged these benign image URLs simply because they are external network addresses. One additional URL points to https://plugins.jetbrains.com/plugin/34642-dublin-theme, which is just a link to another theme on the official JetBrains marketplace. The network endpoints list includes codigrate.com and plugins.jetbrains.com, both of which are expected for an extension fetching its own assets and linking to the official repository. The bash.here string is likely an artifact from a bundled dependency or a false positive string match, as the extension has no process execution capabilities and does not spawn shells.
There are zero malware signatures, zero secret-stealing patterns, and zero obfuscation findings. The two low-severity code-smell findings are standard noise generated by the scanner's rules when inspecting non-trivial JavaScript or configuration files, which is common in bundled webview code or theme generators.
The strongest counterargument to a clean verdict is the sheer volume of findings. A total of 291 alerts is a large number that might alarm an automated triage system or a developer glancing at the summary. However, finding count is a poor proxy for risk when the findings lack malicious context. Every single network indicator in this bundle is a URL to a static image file on the developer's own infrastructure. There is no evidence of postinstall payload execution, no reads of .env or .ssh directories, and no telemetry endpoints sending workspace data to unknown servers. The extension does exactly what a theme is supposed to do: provide color definitions and link to the publisher's resources. The scanner tripped on the repetitive URL pattern in the theme's metadata, mistaking a color palette for a command-and-control infrastructure.
Key Reasons
- All 291 IoC findings are URLs to the publisher's own color swatch images on codigrate.com
- Zero malware signatures, secrets, or obfuscation findings detected
- The extension declares no special permissions or host-level access
- Network endpoints are limited to the publisher's domain and the official JetBrains repository
False Positive Considerations
- XIOC extractor flagging publisher's own color swatch image URLs as malicious IoCs
- High finding count driven entirely by repetitive URL patterns in theme metadata
- Code-smell findings from standard bundled webview or theme configuration files
Reviewed 2026-10-01; recommended action: suppress false positive; model confidence 95%.
JetBrains version history
Risk trend by version
3 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace