Dark Night Mode
bhbekkddpbpbibiknkcjamlkhoghieie
Risk Score
4.43
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy is Google's generic account policy — not scoped to this extension; admits data collection and 3rd-party sharing.
- jQuery 2.2.2 bundles 4 moderate XSS CVEs; fixed version is 3.5.0 — not updated after 17 months.
- No developer name provided; gmail.com dev email reduces accountability.
- <all_urls> host_permissions with content scripts on every visited page broadens attack surface.
- Extension stale at 17 months with unpatched vulnerable library in an extension touching all sites.
Evidence
- generic_privacy_policy store Privacy URL points to Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true → privacy pillar 10.0.
- vulnerable_jquery crx jquery@2.2.2 bundled with 4 moderate CVEs (CVE-2019-11358, CVE-2020-11022, CVE-2020-11023, CVE-2015-9251); fixed in 3.5.0.
- cve_amplifier_applied crx No CSP + moderate CVEs in DOM-manipulation lib (jquery) → CVE pillar ×1.5 amplifier applied.
- no_developer_name store developer_name is empty; only gmail.com contact available, reducing accountability.
- content_scripts_all_urls manifest content_scripts_matches=[<all_urls>] with host_permissions=<all_urls>; JS injected into every visited page.
- verified_publisher_featured store verified_publisher=true and is_featured_by_google=true; partial reputation discount applied (capped at -1.0 due to months_since_update=17>18 threshold near).
- maintenance_stale store Last updated January 2025; 17 months since update → maintenance score 6.0 (6-12 month band).
- no_csp manifest content_security_policy=null on MV3 extension; amplifies CVE risk for bundled jQuery.
CVE Exposures (4)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2019-11358 | jquery@2.2.2 | moderate | 3.4.0 | XSS in jQuery as used in Drupal, Backdrop CMS, and other products |
| CVE-2020-11022 | jquery@2.2.2 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2020-11023 | jquery@2.2.2 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2015-9251 | jquery@2.2.2 | moderate | 1.12.2 | Cross-Site Scripting (XSS) in jquery |
Permissions Breakdown
- tabs medium Can read tab URLs; moderate risk for a theming extension.
- storage low Persists user settings locally; standard for theming tools.
- <all_urls> (host_permissions) high Content scripts injected on every site; necessary for dark-mode but broad surface.
Pillar Scores
Permissions4.00
Reputation5.50
Network0.00
Webstore1.50
Maintenance6.00
Privacy10.00
Code Quality0.00
CVE Exposure4.50
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:20
Listing SHA
9fd3953335e0…
Force block
— not fired
Score recovered
no
Elapsed
26.1s