Dark Mode - Night Eye
alncdjedloppbablonallfbkeiknmkdi
Risk Score
3.67
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- Uninstall URL hijack redirects to nighteye.short.gy (3rd-party URL shortener); +3.0 webstore signal.
- Broad host access (*://*/*) combined with scripting and content_scripts on all URLs; dark-mode category partially justifies.
- 10 innerHTML DOM-XSS sinks across UI and content scripts; CSP is present but sinks remain exploitable via page-supplied data.
- No developer name listed in store; identity pillar elevated.
- 11 external JS hosts including imgbb.com and relayflow.promotino.com; >3 distinct registrable domains raises network concern.
Evidence
- uninstall_url_hijack crx chrome.runtime.setUninstallURL set to https://nighteye.short.gy/rdzkOC/# — 3rd-party URL shortener redirect.
- host_permissions_broad manifest *://*/* with content_scripts on <all_urls>; scripting permission compounds reach.
- dom_xss_sinks crx 10 innerHTML assignments from variables found across background, content, and popup JS files.
- external_hosts_count crx 11 distinct external hosts: billing.nighteye.app, imgbb.com, relayflow.promotino.com, social platforms.
- no_developer_name store developer_name field is empty; only email extensions@promotino.com is present.
- is_featured_by_google store Extension carries Google Featured badge, providing partial trust signal.
- privacy_policy_classification api Policy fetched, scoped to extension, discloses data collection, retention, and third-party sharing.
- cve_findings_raw crx No CVEs detected in bundled JS libraries.
Permissions Breakdown
- storage low Stores user preferences for dark mode settings.
- contextMenus low Adds right-click menu options; low standalone risk.
- activeTab low Scoped to current tab on user action; limited blast radius.
- tabs medium Can read tab URLs and titles across all tabs.
- scripting medium Injects scripts into pages; paired with host_permissions <all_urls> is significant.
- identity medium Can obtain OAuth tokens; risk depends on scopes requested at runtime.
- *://*/* high Broad host access on all URLs; content_scripts also on <all_urls>. Core to dark-mode function but high capability.
Pillar Scores
Permissions5.50
Reputation5.50
Network2.50
Webstore5.50
Maintenance0.00
Privacy1.00
Code Quality2.00
CVE Exposure0.00
Scoring History
| sssiedn16c8d162dp727562726963xsx | 3.42 | Low | review | 2026-09-08 |
| <fsssiedxi"sssiedx | 3.26 | Low | review | 2026-08-14 |
| <fsssiedxa"sssiedx | 4.08 | Medium | review | 2026-08-11 |
| <fsssiedxa sssiedx | 3.48 | Low | review | 2026-08-11 |
| <fsssiedxa'sssiedx | 3.04 | Low | review | 2026-08-11 |
| fsssiedxa<sssiedx | 3.51 | Low | review | 2026-08-11 |
| <fsssiedxf$"sssiedx | 3.57 | Low | review | 2026-08-07 |
| %27fsssiedxg$'sssiedx | 3.61 | Low | review | 2026-08-07 |
| <fsssiedxgfdsaxax><!--></ScRiPt>asddsssiedx | 3.55 | Low | review | 2026-08-07 |
| <fsssiedx{$"sssiedx | 3.74 | Low | review | 2026-08-07 |
| <fsssiedxi$'sssiedx | 3.69 | Low | review | 2026-08-07 |
| <fsssiedxa xx psssiedx | 3.28 | Low | review | 2026-08-07 |
| <fsssiedxa$'sssiedx | 3.26 | Low | review | 2026-08-07 |
| <fsssiedxi xx psssiedx | 3.56 | Low | review | 2026-08-03 |
| <fsssiedxi$"sssiedx | 4.28 | Medium | review | 2026-08-03 |
| <fsssiedxa"sssiedx | 3.63 | Low | review | 2026-08-03 |
| <fsssiedxa$"sssiedx | 3.37 | Low | review | 2026-08-03 |
| <fsssiedxa'sssiedx | 3.52 | Low | review | 2026-07-28 |
| <fsssiedxi"sssiedx | 3.46 | Low | review | 2026-07-28 |
| fsssiedx<sssiedx | 3.51 | Low | review | 2026-07-28 |
| <fsssiedxffdsaxax><!--></ScRiPt>asddsssiedx | 3.27 | Low | review | 2026-07-28 |
| <fsssiedxf"sssiedx | 3.32 | Low | review | 2026-07-28 |
| fsssiedxx sssiedx | 3.49 | Low | review | 2026-07-28 |
| fsssiedxx'sssiedx | 2.86 | Low | review | 2026-07-28 |
| sssieddrubricxsx | 4.11 | Medium | review | 2026-07-28 |
| v3.6 | 3.67 | Low | review | 2026-06-16 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:17
Listing SHA
e61faa454c26…
Force block
— not fired
Score recovered
no
Elapsed
26.2s