Is UI5 Inspector safe?

Low risk

UI5 Inspector lets page scripts trigger injection of extension-packaged scripts into the active tab.

On HTTP and HTTPS pages, UI5 Inspector listens for a page-level CustomEvent and forwards its detail object to the extension background script. That message can request a bundled extension file to be injected into the active tab via chrome.scripting.executeScript.

Part of this rating comes from analysis signals we haven't published as detailed findings yet.

SAP OSSv1.7.0Chrome Web Store
20Risk
Who publishes it

SAP SE - 6 other listings from the same operator, none carrying a finding

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
SAP OSS
Declared legal entity
SAP SE
Registered address
Dietmar-Hopp-Allee 16, Walldorf 69190, DE
Registered contact
OpenUI5

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

What it can do

Permissions this extension asks for, as declared in version 1.7.0. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Read and change your data on every site you visit

    http://*/*

  • Read and change your data on every secure site you visit

    https://*/*

  • Run its own code inside the pages you visit

    scripting

  • Add items to the right-click menu

    contextMenus

  • Act on the current tab, but only after you click the extension

    activeTab

Updated 30 September 2026bebecogbafbighhaildooiibipcnbngo