Is WalkMe Editor Extension safe?
WalkMe Editor injects on every site and can remove Content-Security-Policy and X-Frame-Options headers, gated by remote feature flags.
WalkMe is an enterprise digital-adoption tool that builds and previews in-app guidance overlays, so it runs a content script on every page (<all_urls>) and uses webRequest plus declarativeNetRequest. When enabled by feature flags delivered from WalkMe's own servers, the background service worker strips CSP and X-Frame-Options headers from page responses so the WalkMe player can be embedded. It also exposes a page-callable fetchFromExtension bridge that, when enabled, lets in-page script ask the extension to perform fetches with the extension's broad host permissions; the bridge applies no URL allowlist or requesting-origin check.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.