Is Vue.js devtools safe?
Vue.js devtools runs on all pages to detect Vue.js and exposes build bundles with developer environment metadata to any website.
The extension runs content scripts on every page to detect Vue.js and communicate detection status to the extension's background worker. Its bundled JavaScript files are listed as web-accessible resources readable by any website, and these bundles contain hardcoded developer environment variables such as the build author's username, home directory path, and Node.js paths embedded at build time. A content script also relays postMessage events to chrome.runtime.sendMessage without validating the message origin, allowing any page to trigger UI state changes in the extension.
Part of this rating comes from analysis signals we haven't published as detailed findings yet.
Who publishes itvuejs-dev - 2 other listings from the same operator, none carrying a finding
vuejs-dev - 2 other listings from the same operator, none carrying a finding
What this publisher told the store about itself, and the other listings that told it the same thing.
Same store account
2 other listings published from this account, 140k+ users between them, none of them carrying a finding.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
What it can do
Permissions this extension asks for, as declared in version 7.7.7. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.
Read and change your data on every site you visit
<all_urls>
Run its own code inside the pages you visit
scripting