Is Todoist for Chrome: Planner & Calendar safe?

Medium risk

Todoist for Chrome exposes its popup page to all websites and accepts navigation commands without verifying the sender's origin.

The extension declares popup.html as a web-accessible resource reachable from any URL. The popup listens for postMessage events and, when a message prefixed with 'SWITCH_URL:' arrives, passes the supplied URL to chrome.tabs.update to redirect the user's active tab — without checking event.origin. Any website that embeds the popup in a hidden iframe can silently redirect the user's active tab to an arbitrary URL.

Part of this rating comes from analysis signals we haven't published as detailed findings yet.

Doistv12.21.9Chrome Web Store
45Risk
Who publishes it

Doist Inc. - no other listings under this identity, 1 shared hostname

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
Doist
Declared legal entity
Doist Inc.
Registered address
2100 Geng Road, Palo Alto, CA 94303, US
Registered contact
Ada Bot

Shared hosts - 1 hostname

Hostnames hardcoded in this extension that few other listings call. That can mean one operator behind both, and it can equally mean a small shared vendor, so it is context rather than a conclusion. Hosts that many listings call are left out: they are services, not connections.

d3ptyyxy2at9ui.cloudfront.net
Also called by 3 other listings, including Todoist for Gmail: Planner & Calendar

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Updated 30 September 2026jldhpllghnbhlbpcmnajkpdmadaolakh