Is Todoist for Chrome: Planner & Calendar safe?
Todoist for Chrome exposes its popup page to all websites and accepts navigation commands without verifying the sender's origin.
The extension declares popup.html as a web-accessible resource reachable from any URL. The popup listens for postMessage events and, when a message prefixed with 'SWITCH_URL:' arrives, passes the supplied URL to chrome.tabs.update to redirect the user's active tab — without checking event.origin. Any website that embeds the popup in a hidden iframe can silently redirect the user's active tab to an arbitrary URL.
Part of this rating comes from analysis signals we haven't published as detailed findings yet.
Who publishes itDoist Inc. - no other listings under this identity, 1 shared hostname
Doist Inc. - no other listings under this identity, 1 shared hostname
What this publisher told the store about itself, and the other listings that told it the same thing.
Shared hosts - 1 hostname
Hostnames hardcoded in this extension that few other listings call. That can mean one operator behind both, and it can equally mean a small shared vendor, so it is context rather than a conclusion. Hosts that many listings call are left out: they are services, not connections.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.