Features & Capabilities

Sealist 🦭

A browser extension offering seamless E2E encryption for Todoist. Basically, this cutie seals your tasks and comments only for you to see.

Background

What Todoist Already Does

See Todoist Security Policy.

  • All user data is encrypted at rest in their production database.
  • Encryption is keyed by a master key held by Todoist.
It stops the stolen-hard-drive attack. What it doesn't stop:
  • Master key compromise or misuse.
  • A court order or legal compulsion.
  • A breach of the live app stack - prod read access means plaintext access, employee or attacker alike.
  • A future policy change on who gets to read your content.
  • Cross-border data-sharing pressures.
The Goal

Move the trust boundary off Todoist's server and onto the user's browser. Encrypt before task leaves, decrypt on the way back. Todoist's servers see opaque ciphertext. Plaintext only ever exists inside the browser client while the extension is Unsealed.

We want to provide a similar model to Mailvelope/FlowCrypt which layer PGP onto Gmail, but without requiring users setting PGP keys.

We should not make Todoist that much worse to use :p. The crypto should be conservative and audited. The codebase must be small enough to read. The shortcomings must be documented honestly.

Non Goals

We are not trying to defeat:

  • Malware running on the user's machine with arbitrary access (extension memory, screenshots, key loggers).
  • A malicious extension installed by the user with the same host_permissions reading our injected DOM. Extensions are isolated from each other's in-memory state and storage, but not from a malicious extension reading the page we both render to.
  • A user picking a low-entropy password. We gate on password complexity and employ a memory-hard KDF to make the offline attack as expensive as we honestly can, but a determined adversary wins against low-entropy passwords if one would pass the checks.

License

Copyright (C) 2026 yaspltbr

This program is free software: you can redistribute it and/or modify it under the terms of the GNU General Public License as published by the Free Software Foundation, either version 3 of the License, or (at your option) any later version.

IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.

User Growth & Download Statistics

Manifest V2 Add-on
By:
yaspltbr
Daily users:
1
Rating:
5.00
(2)
Version:
1.0.3 Last updated: 2026-06-22
Version code:
6315026
Creation date:
2026-06-19
Risk:
Low risk impact High risk likelihood
Permissions:
  • storage
  • https://app.todoist.com/*
  • https://api.todoist.com/*
Content scripts matches:
  • app.todoist.com
Size:
321.99KB
URLs:
Website
Full description:
See detailed description
Source:
Firefox Add-ons Store
Data ingested on:
2026-07-27
Compare stats and ranking:

Contact the developer

Chrome-Stats does not own this Firefox add-on. Please use these information below to contact the Firefox add-on developer.
Developed by:
yaspltbr
Firefox Add-ons Store
https://addons.mozilla.org/firefox/addon/sealist/
Website:
https://gitlab.com/yaspltbr/sealist

User Reviews

That is exactly what I was looking for
by Pa*****, 2026-06-23

by ko*****, 2026-06-22
View all user reviews ›

Is Sealist Safe?

Risk impact
Risk impact measures the level of extra permissions an extension has access to. A low risk impact extension cannot do much harms, whereas a high risk impact extension can do a lot of damage like stealing your password, bypassing your security settings, and accessing your personal data. High risk impact extensions are not necessarily malicious. However, if they do turn malicious, they can be very harmful.

Sealist requires very minimum permissions.

Risk impact analysis details
  • High Injects scripts into web pages, which may alter or extract site contents, resulting in a substantial risk.
  • Low ******* ****** ** *** ********* ******** ***********
Risk likelihood
Risk likelihood measures the probability that a Firefox add-on may turn malicious. This is determined by the publisher and the Firefox add-on reputation on Firefox Add-ons Store, the amount of time the Firefox add-on has been around, and other signals about the Firefox add-on. Our algorithms are not perfect, and are subject to change as we discover new ways to detect malicious extensions. We recommend that you always exercise caution when installing a Firefox add-on.

Sealist is recently added, and hasn't been around long enough for us to gather enough data to accurately assess its risk level.

Risk likelihood analysis details
  • High This extension has low user count. Unpopular extensions may not be stable or safe.
  • Medium **** ********* *** ******* ** *** **** * ******* *** ******* *** *** ** ****** ** *****
  • Medium **** ********* *** ***** ** *** **** * ******* *** ********** *** *** ** ****** ** *****
  • Good **** ********* *** **** **** *******
Extension Guard
Extension Guard

Discover every extension in use, analyze risks, and enforce blocking policies with Extension Guard

Secure Your Browser
Upgrade to see full risk analysis details

Best Sealist Alternatives

Here are some Firefox add-ons that are similar to Sealist: