Is Sidebar for Google Tasks safe?

Clean risk

Sidebar for Google Tasks removes Content-Security-Policy and X-Frame-Options headers from tasks.google.com to embed it in a browser side panel.

The extension adds a declarativeNetRequest rule that strips CSP and X-Frame-Options response headers from tasks.google.com on every matching sub-frame request, and also spoofs the Referer header to mail.google.com. This allows the extension to load the Google Tasks web app inside an iframe in its side panel, bypassing Google's own embedding restrictions. No user data is transmitted to third parties; the modification is local and targets only tasks.google.com.

BrowseCraftv26.4.4Chrome Web Store
0Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Updated 17 September 2026jlgndcbgcfaaidgacjgelccmedbjenhb