Tasks - To do & task list by Workona
dneiffjipkkinmcpploifdknmhlmfbhc
Risk Score
3.54
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- Privacy policy covers workona.com broadly but does not scope data collection to THIS extension; admits 3rd-party sharing.
- Extension not updated for 24 months — at boundary of stale threshold.
- No CSP defined (MV3 mitigates somewhat, but adds minor risk surface).
- Developer name field empty in manifest; reduces accountability signal.
- Privacy policy scores max (10) due to scope_extension=false + data_collection=true + third_party_sharing=true per v3.5 D rule.
Evidence
- privacy_policy_scope_mismatch api Policy fetched but scope_extension=false, data_collection=true, third_party_sharing=true → generic policy admitting 3rd-party sharing.
- maintenance_stale store Last updated June 2024; months_since_update=24, triggering +6.0 maintenance score.
- no_csp manifest content_security_policy is null; MV3 provides default CSP but no explicit policy declared.
- featured_by_google store is_featured_by_google=true; follows recommended practices badge provides -2.0 reputation discount.
- clean_threat_intel api No bad_host_hits, affiliate_hits, or monetization_hits. Developer domain workona.com resolves, not throwaway.
- clean_code crx code_findings_raw empty, obfuscation_score=0.0, no CVEs detected in 2 scanned JS files.
- scoped_host_permissions manifest Host permissions limited to workona.com and *.workona.com only; no broad host access.
- no_operator_cluster api sibling_count=0; no related suspicious extensions under same fingerprint.
Permissions Breakdown
- tabs medium Can read tab URLs and titles; limited scope with only workona.com host access.
- storage low Local data persistence for task list; standard productivity use.
- host: https://workona.com/* low Scoped to developer-owned domain only; expected for sync functionality.
- host: https://*.workona.com/* low Subdomain wildcard on dev-owned domain; reasonable for backend API calls.
Pillar Scores
Permissions1.30
Reputation3.50
Network2.00
Webstore1.00
Maintenance6.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:28
Listing SHA
520e92e98aaf…
Force block
— not fired
Score recovered
no
Elapsed
20.3s