Wrike ToDo list
eopgmefbafmikfhhbdinpdpbiicbchce
Risk Score
3.72
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- Privacy policy is Google's generic policy (scope_extension=false, data_collection=true, third_party_sharing=true) — not scoped to this extension at all.
- NewTab override: replaces every new-tab page; install_url_hijack redirects to chrome://newtab on install.
- Developer domain team.wrike.com does not resolve, weakening accountability signal.
- CSP allows cdn.jsdelivr.net for img-src and fonts.googleapis.com/fonts.gstatic.com for font/style; minor scope creep.
- Rating 3.9 and no verified-publisher badge for a recognized SaaS vendor; unverified identity.
Evidence
- privacy_policy_generic store Policy URL is Google Account policy; scope_extension=false, data_collection=true, third_party_sharing=true — triggers D rule (+10.0 privacy).
- newtab_override manifest chrome_url_overrides.newtab = index.html; every new tab is controlled by this extension.
- install_url_hijack crx onInstalled opens chrome://newtab (internal), not a 3rd-party URL; low monetization risk.
- developer_domain_no_resolve api threat_intel.developer_domain_info.resolves=false for team.wrike.com; reduces accountability.
- no_verified_publisher store verified_publisher=false, is_featured_by_google=false; Wrike is a known SaaS but not badge-verified here.
- cve_findings_clean crx No CVEs detected; no bundled vulnerable JS libraries.
- code_findings_clean crx code_findings_raw empty, obfuscation_score=0.0; no malicious code patterns.
- threat_intel_clean api bad_host_hits, affiliate_hits, monetization_hits all empty; no ad-tech or threat hosts.
Permissions Breakdown
- identity low Used for OAuth login flow to Wrike; no broad scopes declared.
- storage low Local state persistence; low standalone risk.
- tabs medium Can read tab URLs and titles; moderate risk without host access.
- host: https://www.wrike.com/ low Scoped to developer's own domain; expected for task sync.
- host: https://*.chromiumapp.org/* low Required for OAuth redirect flow in Chrome identity API.
- chrome_url_overrides.newtab medium Replaces new-tab page; high-visibility surface, moderate risk.
Pillar Scores
Permissions2.30
Reputation4.50
Network1.50
Webstore4.50
Maintenance1.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:32
Listing SHA
e505b8b7543f…
Force block
— not fired
Score recovered
no
Elapsed
23.1s