Asana
khnpeclbnipcdacdkhejifenadikeghk
Risk Score
4.02
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy not scoped to this extension; admits data collection and third-party sharing without extension-specific disclosure (+10.0 privacy).
- Dynamic script injection in sidebar.js and background_bundle.js could load remote code at runtime (script_src_dynamic).
- Content script on Gmail (mail.google.com) gives access to email content — high-sensitivity surface.
- Extension last updated 22 months ago; no security patches for nearly 2 years.
- No CSP declared (MV3 so no v2 penalty, but dynamic script creation without CSP raises runtime trust boundary concerns).
Evidence
- verified_publisher + featured store Asana is a verified publisher and Google-featured extension; reputation floor capped at 2.0.
- privacy_policy_scope_miss api Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true → D rule applies: +10.0 privacy.
- script_src_dynamic x2 crx Dynamic <script> creation found in sidebar.js and background_bundle.js; no CSP to constrain destination.
- gmail_content_script manifest Content script injected into mail.google.com — can observe and modify email DOM.
- stale_extension store 22 months since last update; maintenance score +6.0 (6-24mo band).
- no_csp manifest content_security_policy is null; MV3 default applies but dynamic script findings add risk.
- js_external_hosts crx js_external_hosts includes www.example.com — placeholder or test artifact; low impact but noteworthy.
- threat_intel_clean api No bad_host_hits, monetization_hits, or affiliate_hits; developer domain resolves; sibling_count=0.
Permissions Breakdown
- cookies high Can read/write cookies; scoped only to asana.com and mail.google.com by host_permissions.
- activeTab low Transient access to current tab on user gesture only.
- scripting medium Can inject scripts; scoped to declared host permissions.
- storage low Local extension storage only, no cross-site exfil risk by itself.
- contextMenus low UI integration only, no data access.
- tabs medium Can read tab URLs and titles across all tabs.
- clipboardWrite medium Can write to clipboard; no read capability declared.
- https://*.asana.com/* medium Broad subdomain access scoped to first-party Asana domain.
- https://mail.google.com/* high Content script injected into Gmail; can read email content and interact with mail UI.
Pillar Scores
Permissions4.50
Reputation2.00
Network3.00
Webstore1.00
Maintenance6.00
Privacy10.00
Code Quality3.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:34
Listing SHA
6b0c5967c690…
Force block
— not fired
Score recovered
no
Elapsed
—