Skip to content

Analysis scope

KAEV first builds a project fingerprint and then runs only applicable checks. It recognizes SAPUI5 and OpenUI5 application, component, library, theme-library, module, Fiori Elements, freestyle, TypeScript, JavaScript, OData V2/V4, CAP, ABAP, and common legacy project evidence. Unknown information remains unknown; KAEV does not invent versions from unrelated metadata.

KAEV reads ui5.yaml, manifest.json, package metadata, configured resource paths, model declarations, imports, constructors, and common legacy layouts. UI5 runtime, minimum runtime requirement, UI5 configuration specification, and UI5 CLI dependency version are tracked as separate facts.

Configured paths must remain inside the project. Windows separators are accepted and normalized to portable / workspace paths.

Supported text extensions are .js, .ts, .mjs, .cjs, .json, .yaml, .yml, .xml, and .html.

KAEV excludes dependencies, VCS metadata, build output, coverage, caches, generated/vendor/third-party directories, tests, fixtures, minified JavaScript, declarations, preload bundles, package lockfiles, symlinks, binary files, and files larger than 1 MiB.

Discovery is bounded to:

  • 1 MiB per file.
  • 50 MiB total analyzed source.
  • 30,000 filesystem entries.
  • Directory depth 32.

Reaching a limit produces a diagnostic and partial coverage rather than silently claiming a complete analysis.

  • JavaScript and TypeScript use the TypeScript parser; KAEV does not execute source.
  • JSON is strict, YAML aliases are bounded, and XML DTDs are rejected.
  • Constant strings include safe literals, templates, and concatenations. Dynamic values are not fabricated into fake URLs.
  • Local aliases, lexical scope, shadowing, reaching assignments, await, parentheses, and TypeScript wrappers are followed with depth and cycle limits.
  • OData V2 tracing covers known models, read callbacks, and getProperty collections.
  • OData V4 tracing covers model bindings and locally requested contexts while distinguishing UI5 binding filters/sorters from JavaScript array processing.

KAEV is not a full interprocedural or runtime taint engine. Indirect helper cleanup, base-class behavior, dependency code, dynamically computed receivers, and arbitrary cross-function flows may require manual review.

  • Heuristic findings are evidence for review, not proof of a defect or exploit.
  • Dynamic HTML does not prove XSS.
  • Manual OData writes do not prove a CSRF vulnerability.
  • Client-side role checks do not prove missing backend authorization.
  • Global Core access is modernization guidance, not a blanket claim that every use is invalid.
  • Stable-ID analysis focuses on selected sap.m controls in applicable flexibility-enabled freestyle apps.
  • Timer lifecycle analysis focuses on repeating intervals, not every self-terminating timeout.

KAEV does not replace UI5 tooling, backend authorization tests, integration/browser tests, dependency auditing, penetration testing, or professional security review.