VS Code Marketplace Verified

SAPUI5 Manager

by UISAP Bilgi Teknolojileri · 476 users · 5.0 rating
3c9be1a1-0200-5613-a30c-d7f67790c75f | v0.0.5
31/ 100
LOW risk
-10 since v0.0.4
Analyst verdict
No high-risk signal observed

Based on the RiskyPlugins AI security review of the observed evidence.

Analysis record

Analysed
6 months ago
Version
v0.0.5
Artifact
SHA256 ACC…28A
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

3 detail rows

Publisher Evidence

Limited evidence

UISAP Bilgi Teknolojileri

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

32
Noisy-finding weight
x1.00
Publisher domain
uisap.com
Observed
Store verification signal
Not exposed
Not exposed
Extension portfolio
1
Portfolio

13 evidence rows available.

Finding Categories

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality moderate.

The SAPUI5 Manager extension is a legitimate development tool for SAP BSP Upload & Download operations. Filesystem and process access for this extension is justified by its stated purpose of managing SAPUI5 application files.

Filesystem/Process Access Justification: The extension description states it handles "SAP BSP Upload & Download Manager for SAPUI5 Applications." File read/write operations for SAP development tools are expected behavior—this is the extension's core function. No findings indicate postinstall payload execution, unauthorized command spawning, or code execution beyond legitimate development tool operations. The 21 code-smell findings (severity=low) match expected patterns for any non-trivial JavaScript bundle and do not indicate malicious intent.

Credential Access Findings: There are zero secret/credential findings in this evidence bundle. The findings_summary shows "secret":"0" and no findings target .env, .ssh, cloud credentials, or VS Code secret storage. This is appropriate for a file management extension that does not require credential access to function.

IoC Findings Analysis: All 251 medium-severity IoC findings are XIOC extractor false positives. The specific findings demonstrate the known garbage pattern: XIOC-DOMAIN-g.call, XIOC-DOMAIN-n.next, XIOC-DOMAIN-this.axiosinstance.post, XIOC-DOMAIN-e.read, XIOC-DOMAIN-h.open are all property access chains misidentified as domains. These are not valid DNS domains—they are JavaScript method calls on objects. The this.axiosinstance.post finding references axios, a legitimate HTTP library commonly used in Node.js applications for network requests.

Strongest Counterargument: The volume of 251 IoC findings could suggest malicious network activity. However, this does not change the conclusion because: (1) zero malware-signature findings, (2) zero obfuscation findings, (3) zero secret findings, (4) zero network findings, and (5) all IoC findings match the documented XIOC property-access-chain false-positive pattern. Finding count is noise; finding nature is signal. The absence of any high-severity or critical findings, combined with the complete lack of malware signatures or credential theft indicators, confirms these are false positives from bundled/minified JavaScript.

This extension has 219 users on VS Code and appears to serve a legitimate SAP development workflow. The findings pattern matches the known false-positive documentation exactly.

Key Reasons

  • All 251 IoC findings are property access chains, not real domains
  • Zero malware signatures or obfuscation findings
  • Zero credential/secret findings
  • Extension purpose justifies file access
  • No postinstall payload or exfiltration evidence

False Positive Considerations

  • XIOC property access chain extraction (g.call, n.next, e.read)
  • Code-smell findings on bundled JavaScript (21 low-severity)
  • Bundled dependency noise (axios HTTP library)
  • Minified/dist file YARA matches

Reviewed 2026-04-27; recommended action: suppress false positive; model confidence 88%.

VS Code version history

Risk trend by version

2 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
31
Change since first
-10
Change from previous
-10
Versions:
First analyzed version
0.0.4
Feb 8, 2026
Risk range
31 to 42
Across analyzed versions
Latest analyzed version
0.0.5
Apr 5, 2026
Selected version
low
Version
v0.0.5
5 months ago
Risk score
31
Findings
3
Change vs previous
-10

Pick any point on the chart to explore that version's code below.

About This Extension

SAP BSP Upload & Download Manager for SAPUI5 Applications

Frequently Asked Questions