OpenVSX Registry

SAPUI5 Manager

00005178-4a92-5894-bfce-0b532a365078 | v0.0.5
31/ 100
LOW risk
Analyst verdict
No high-risk signal observed

Based on the RiskyPlugins AI security review of the observed evidence.

Analysis record

Analysed
6 months ago
Version
v0.0.5
Artifact
SHA256 ACC…28A
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

3 detail rows

Publisher Evidence

Limited evidence

uisap-tech

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

20
Noisy-finding weight
x1.00
Publisher domain
No domain
Missing
Store verification signal
Not exposed
Not exposed
Extension portfolio
1
Portfolio

13 evidence rows available.

Finding Categories

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality moderate.

Security Analysis: SAPUI5 Manager

Filesystem and Process Access Justification

The extension "SAPUI5 Manager" by developer "uisap-tech" is described as an "SAP BSP Upload & Download Manager for SAPUI5 Applications." This stated purpose legitimately requires filesystem read/write operations for uploading and downloading files to SAP backend systems. The findings bundle contains zero malware signatures, zero credential findings, and zero secret findings. The 21 code-smell findings are all classified as low severity, which per CVEQ guidelines represents expected IDE extension behavior and should be treated as noise.

Credential Access Assessment

No credential-access findings target actual secrets. The findings summary shows "secret":0 and "credential":0 in the by_category breakdown. There are no findings referencing .env, .ssh, cloud credentials, or VS Code secret storage. The extension does not demonstrate credential theft patterns.

IoC Finding Analysis

All 251 medium-severity IoC findings are false positives from the XIOC extractor misinterpreting JavaScript property access chains as domain names. Specific examples include:

  • XIOC-DOMAIN-this.axiosinstance.post - This is an axios HTTP client method call, not a domain
  • XIOC-DOMAIN-a.response.data - This is object property access in JavaScript
  • XIOC-DOMAIN-h.open - This is a function call, not a network domain
  • XIOC-DOMAIN-n.next - This is an iterator method, not a domain
  • XIOC-DOMAIN-o.protocols.map - This is object property chaining

These match the documented XIOC garbage pattern: "Property access chains misread as domains: b.call, h.next, g.id". None of these findings represent actual network domains or infrastructure connections.

Strongest Counterargument

The strongest counterargument is the extension's presence on OpenVSX with 747 users and version 0.0.5, which suggests an early-stage extension without verified marketplace status. However, this does not constitute evidence of malicious behavior. The high finding count (275 total) is inflated by false positive patterns, not actual threat indicators. The absence of any high or critical severity findings, combined with zero malware signatures and zero credential findings, confirms these are noise findings from known XIOC false positive patterns rather than indicators of malicious intent.

Conclusion

This extension exhibits no evidence of malicious behavior. All findings derive from documented false positive sources: XIOC property access chain misinterpretation and low-severity code-smell patterns. The extension's stated purpose (SAP file management) justifies expected IDE capabilities.

Key Reasons

  • All 251 IoC findings are property access chains misread as domains
  • Zero malware signatures detected in any category
  • Zero credential or secret findings present
  • Extension purpose justifies expected IDE capabilities
  • No high or critical severity findings

False Positive Considerations

  • XIOC property access chain misinterpretation as domains
  • Low-severity code-smell findings on IDE extension patterns
  • No actual malware signatures or credential findings
  • Zero obfuscation or secret detection findings

Reviewed 2026-04-27; recommended action: suppress false positive; model confidence 85%.

About This Extension

SAP BSP Upload & Download Manager for SAPUI5 Applications

Frequently Asked Questions