Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Dark Reader

eimadpbcbfnmbkopoojfekhnkhdbieeh
Risk Score
2.65
Risk Level: Low
Recommendation: ✅ ALLOW
Category Accessibility
Installs 7,000,000
Rating 4.7
Last updated 2026-09-02
Manifest version MV3
CSP present ✅ yes
Developer support@darkreader.org
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • *://*/* host access + scripting gives full page read/write on every site visited.
  • Privacy policy fetched but scope_extension==false and third_party_silence==true; retention not disclosed.
  • No developer_name listed in store; darkreader.org is legitimate but not verified-publisher.
  • connect-src * in CSP allows extension pages to contact any server.
  • raw.githubusercontent.com in external JS hosts could serve dynamic content if misused.

Evidence

  • broad_host_access manifest host_permissions *://*/* + content_scripts <all_urls>; justified for dark-mode category.
  • is_featured_by_google store Extension carries Google Featured badge; -2.0 reputation discount applied.
  • clean_threat_intel api No bad_host_hits, affiliate_hits, or monetization_hits; developer domain resolves.
  • no_code_findings crx code_findings_raw empty; obfuscation_score 0.0; no exfil or eval indicators.
  • privacy_policy_scope_gap api Policy fetched but scope_extension=false, retention=false; third_party_silence=true.
  • csp_connect_src_broad manifest CSP connect-src * allows extension pages to reach arbitrary hosts; +2.5 network.
  • recently_updated store Last updated April 2026; 2 months ago; maintenance score 0.0.
  • no_cve_findings crx cve_findings_raw empty; CVE pillar 0.0.

Permissions Breakdown

  • alarms low Schedules periodic tasks; minimal risk.
  • fontSettings low Read/write browser font settings; narrow scope.
  • scripting medium Allows injecting scripts into pages; elevated but expected for dark-mode tool.
  • storage low Local preference persistence; low risk.
  • host_permissions: *://*/* high Broad host access needed for dark-mode CSS injection on all sites; -1.5 justified-broad discount applied.
  • content_scripts: <all_urls> high Content scripts on all URLs; matches stated function, discount applied.

Pillar Scores

Permissions4.10
Reputation3.00
Network2.50
Webstore2.50
Maintenance0.00
Privacy6.00
Code Quality0.00
CVE Exposure0.00

Scoring History

sssiedn2c23eeccdp727562726963xsx 2.74 Low allow 2026-09-09
v3.6 2.65 Low allow 2026-06-16

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:30
Listing SHA bfb095ab1d5b…
Force block — not fired
Score recovered no
Elapsed 20.6s