Is Pomodoro Chrome Extension safe?

Clean risk

Pomodoro Chrome Extension ships a Google OAuth client secret in its iframe bundle.

The extension bundle contains Google OAuth client ID and client secret values as readable strings. Its Google sign-in flow builds an accounts.google.com OAuth URL with a redirect URI on bashvlas.com, so the OAuth secret is recoverable from the installed extension source rather than kept server-side.

Chromanev2.2.2Chrome Web Store
0Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

What it can do

Permissions this extension asks for, as declared in version 2.2.2. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Store data in your browser

    storage

  • Schedule its own background tasks

    alarms

Where it sends data

Destinations our analysis observed Pomodoro contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.

  • accounts.google.com

    Pomodoro sends data to accounts.google.com. One other extension we have analysed sends data here.

  • bashvlas.com

    Pomodoro sends data to bashvlas.com. No other extension we have analysed sends data here.

Updated 30 September 2026iccjkhpkdhdhjiaocipcegfeoclioejn