Dark Mode
dmghijelimhndkbmpgbldicpogfkceaj
Risk Score
4.85
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy is Google's generic account policy — not scoped to this extension at all, collecting and sharing user data admitted.
- Gmail developer with no business domain; unverifiable identity behind 2M-install extension with <all_urls>.
- install_url_hijack and uninstall_url_hijack flags set; onInstalled/setUninstallURL to undisclosed third-party URL.
- 8 external JS hosts referenced (github, youtube, mybrowseraddon, webbrowsertools, etc.) — broad external linkage with no CSP.
- Rating 3.6 on a 2M-install extension suggests user dissatisfaction; no review red-flags captured but low rating is a quality signal.
Evidence
- install_url_hijack + uninstall_url_hijack both true crx Extension registers onInstalled and setUninstallURL hooks to undisclosed targets — standard monetization shell pattern.
- privacy_policy generic Google account policy store scope_extension=false, data_collection=true, third_party_sharing=true → D clause: +10.0 privacy pillar.
- developer email is gmail.com free-webmail store grephyr.prj@gmail.com; no business domain; domain_age_ct not queried (free_webmail_or_no_email).
- host_permissions <all_urls> + content_scripts <all_urls> manifest Full page access on every site; broad reach for a dark-mode theme extension.
- 8 external JS hosts, no CSP (MV3) crx Hosts: github.com, jakiestfu.com, mjijackson.com, mybrowseraddon.com, opensource.org, stackoverflow.com, webbrowsertools.com, youtube.com.
- is_featured_by_google = true store Featured badge partially mitigates reputation; not verified publisher.
- rating 3.6 on 2M installs store Below-average rating at massive scale; no specific review red-flags detected.
- operator_cluster dev_email sibling_count=4 api Same gmail address linked to 4 sibling extensions by dev_email dimension.
Permissions Breakdown
- storage low Stores user preferences locally; low risk.
- contextMenus low Adds right-click menu items; low risk.
- <all_urls> (host_permissions) high Content script injection on every site; broad reach for a theme tool.
Pillar Scores
Permissions3.50
Reputation7.00
Network2.00
Webstore7.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Scoring History
| sssiedn0f581a0cdp727562726963xsx | 5.14 | Medium | review | 2026-09-08 |
| <fsssiedxi xx psssiedx | 4.49 | Medium | review | 2026-08-20 |
| <fsssiedxi'sssiedx | 4.84 | Medium | review | 2026-08-20 |
| <fsssiedxi | 4.73 | Medium | review | 2026-08-20 |
| <fsssiedxi$"sssiedx | 5.20 | Medium | review | 2026-08-20 |
| <fsssiedxafdsaxax><!--></ScRiPt>asddsssiedx | 4.78 | Medium | review | 2026-08-20 |
| <fsssiedxa xx psssiedx | 4.42 | Medium | review | 2026-08-20 |
| <fsssiedxa | 4.71 | Medium | review | 2026-08-20 |
| <fsssiedxa$'sssiedx | 4.71 | Medium | review | 2026-08-20 |
| fsssiedx<sssiedx | 5.13 | Medium | review | 2026-08-20 |
| sssieddrubricxsx | 4.87 | Medium | review | 2026-07-31 |
| v3.6 | 4.85 | Medium | review | 2026-06-16 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:28
Listing SHA
2cbca2f85980…
Force block
— not fired
Score recovered
no
Elapsed
24.0s