Is Pomodoro Chrome Extension safe?
Pomodoro Chrome Extension ships a Google OAuth client secret in its iframe bundle.
The extension bundle contains Google OAuth client ID and client secret values as readable strings. Its Google sign-in flow builds an accounts.google.com OAuth URL with a redirect URI on bashvlas.com, so the OAuth secret is recoverable from the installed extension source rather than kept server-side.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
What it can do
Permissions this extension asks for, as declared in version 2.2.2. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.
Store data in your browser
storage
Schedule its own background tasks
alarms
Where it sends data
Destinations our analysis observed Pomodoro contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.
- accounts.google.com
Pomodoro sends data to accounts.google.com. One other extension we have analysed sends data here.
- bashvlas.com
Pomodoro sends data to bashvlas.com. No other extension we have analysed sends data here.