Toggl Track: Productivity & Time Tracker
oejgccbfbmkkpaidnkphaiaecficdnfn
Risk Score
4.05
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Critical CVE-2021-23358 in bundled underscore@1.8.3 (Arbitrary Code Execution); not patched.
- High CVE-2026-27601 in underscore@1.8.3 (DoS via recursion); not patched.
- Privacy policy fetched but scope_extension==false and admits 3rd-party data sharing without extension-specific scope → +10.0 privacy pillar.
- No developer name listed in store; email domain toggl.com resolves but publisher not verified.
- Uninstall URL hijack flag set true; though target null, signal warrants review.
Evidence
- cve_critical crx underscore@1.8.3 bundles CVE-2021-23358 (Arbitrary Code Execution); fixed in 1.12.1.
- cve_high crx underscore@1.8.3 bundles CVE-2026-27601 (DoS recursion); fixed in 1.13.8.
- privacy_scope_missing store Policy at toggl.com/legal/track/privacy/ does not scope to this extension; admits 3rd-party sharing.
- uninstall_url_hijack crx uninstall_url_hijack==true; target URL null so hijack destination unknown.
- cookies_permission manifest cookies permission declared; host-scoped to toggl.com only, limiting blast radius.
- featured_by_google store Extension marked is_featured_by_google=true; positive trust signal.
- no_code_findings crx code_findings_raw empty, obfuscation_score=0.0; no active malicious behaviour detected.
- external_hosts crx 12 external JS hosts including momentjs.com, radix-ui.com, robwu.nl outside toggl.com cluster.
CVE Exposures (2)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2021-23358 | underscore@1.8.3 | critical | 1.12.1 | Arbitrary Code Execution in underscore |
| CVE-2026-27601 | underscore@1.8.3 | high | 1.13.8 | Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS |
Permissions Breakdown
- alarms low Schedules timer reminders; expected for time tracker.
- background low Keeps timer running in background; expected.
- contextMenus low Adds right-click timer controls; low risk.
- idle low Detects idle to pause timer; expected function.
- notifications low Timer alerts; expected for productivity tool.
- scripting medium Can inject scripts into pages; scoped to toggl.com host perms.
- storage low Local config/state; standard.
- cookies high Can read cookies; host-scoped to toggl.com only, reduces blast radius.
- offscreen low Offscreen document for audio/DOM; low risk.
- unlimitedStorage low Extended local storage for time entries; expected.
Pillar Scores
Permissions3.50
Reputation4.00
Network2.50
Webstore1.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure7.00
Scoring History
| v3.6 | 4.05 | Medium | review | 2026-06-16 |
| v3.4-rev | 3.12 | Low | review | 2026-06-15 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 08:00
Listing SHA
23b1ac1aacbc…
Force block
— not fired
Score recovered
no
Elapsed
25.4s