Dark Mode for Chrome
epbpdmalnhhoggbcckpffgacohbmpapb
Risk Score
3.97
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- Broad host permissions (*://*/*) with content scripts on every page — high-capability for a dark-mode tool.
- Developer uses free Gmail address with no verified business identity; no dev name listed.
- Privacy policy lacks retention clause; third-party sharing is silent.
- Extension 16 months stale — supply-chain takeover risk window is open.
- No CSP declared; elevated injection risk if future code changes occur.
Evidence
- broad_host_permissions manifest host_permissions include *://*/* and content_scripts_matches *://*/* — runs on every page.
- gmail_developer store Developer email bellowmaixinoom@gmail.com; no dev name; free webmail with no verified business.
- verified_publisher_featured store verified_publisher=true AND is_featured_by_google=true; discounts applied but capped at -1.0 (stale >12mo).
- privacy_policy_retention_missing api Policy fetched, scoped, data_collection=true, but retention=false and third_party_silence=true.
- no_csp manifest content_security_policy is null on MV3; +2.0 Network penalty applied.
- maintenance_stale store Last updated Feb 2025, 16 months ago — 12-24mo band (+6.0 raw maintenance score).
- no_bad_hosts_no_cves api threat_intel bad_host_hits=[], cve_findings_raw=[], code_findings_raw=[]; no active threat signals.
- operator_cluster_clean api sibling_count=0; no affiliated sibling extensions detected.
Permissions Breakdown
- fontSettings low Allows reading/changing browser font settings; limited blast radius.
- activeTab low Scoped to current tab on user gesture; low standalone risk.
- storage low Local preference storage; no exfil path alone.
- tabs medium Exposes URL/title of all open tabs; moderate info-disclosure risk.
- alarms low Scheduling only; no data access.
- *://*/* high Broad host permission — content scripts injected on every HTTP/S page.
- *://*/*/* high Redundant broad host permission; same surface as *://*/*.
Pillar Scores
Permissions5.50
Reputation5.50
Network2.00
Webstore1.50
Maintenance6.00
Privacy2.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:32
Listing SHA
91ac9baf3fc0…
Force block
— not fired
Score recovered
no
Elapsed
24.2s