Is Vue.js devtools safe?

Medium risk

Vue.js devtools forwards captured timeline screenshots into the inspected page through a window.postMessage bridge.

When the Devtools panel is open, Vue.js devtools can capture visible-tab screenshots for timeline events. If a timeline screenshot is shown, the extension sends that screenshot object through a page-level window.postMessage bridge, making it available inside the inspected page rather than a remote server.

Part of this rating comes from analysis signals we haven't published as detailed findings yet.

vuejs-devv6.6.4Chrome Web Store
42Risk
Who publishes it

vuejs-dev - 2 other listings from the same operator, none carrying a finding

What this publisher told the store about itself, and the other listings that told it the same thing.

Same store account

2 other listings published from this account, 1.0M+ users between them, none of them carrying a finding.

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

What it can do

Permissions this extension asks for, as declared in version 6.6.4. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Read and change your data on every site you visit

    <all_urls>

  • Store data in your browser

    storage

  • Run its own code inside the pages you visit

    scripting

Updated 30 September 2026iaajmlceplecbljialhhkmedjlpdblhp