Dark Mode for Shopify
hfoeimdgmlholdmiodhkeohhnjjkddhp
Risk Score
5.61
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy is Google's own policy (not scoped to this extension) and admits data collection + third-party sharing — scored as worst-case.
- Extension is 37 months stale (>36mo), maintenance pillar maxed at 10.0.
- Brand impersonation: 'Shopify' named without confirmed owner affiliation; verified+featured discount applies but still +1.0.
- Privacy policy admits data_collection=true AND third_party_sharing=true but scope_extension=false — generic Google policy with no extension scope.
- Content scripts run on Shopify admin (authenticated merchant dashboard); any future supply-chain compromise has high-value target reach.
Evidence
- privacy_policy_generic_google store Privacy URL points to Google's own account policy; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 Privacy.
- stale_37mo store Last updated May 2023; months_since_update=37 → maintenance pillar 10.0 + zombie booster not triggered (installs<10K).
- brand_impersonation_shopify store brand_mention.is_impersonation=true, confirmed_owner=false; verified+featured → +1.0 Reputation per v3.2.
- install_url_hijack crx install_url_hijack=true but install_url_target=null; cannot confirm 3rd-party target, scored conservatively as +2.0 Webstore.
- monetization_google_analytics crx monetization_hits: google-analytics.com (telemetry tier) → +1.0 Webstore (telemetry-tier only).
- dom_sink_innerhtml crx dom_sink_innerhtml_userctrl in popup.js; CSP present, no eval/CVE co-trigger → +0.5 Code Quality.
- verified_publisher_featured store verified_publisher=true AND is_featured_by_google=true; discount capped at -1.0 (v3.5E) due to monetization_hits non-empty.
- no_developer_name store developer_name is empty string; +1.0 Reputation for no 'Offered by' name.
Permissions Breakdown
- storage low Used to persist dark-mode preference locally; no exfil surface.
- content_scripts: *.myshopify.com/admin*, accounts.shopify.com, admin.shopify.com medium Injects JS into Shopify admin pages; scoped but runs on authenticated merchant pages.
Pillar Scores
Permissions0.30
Reputation6.00
Network0.00
Webstore5.50
Maintenance10.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:39
Listing SHA
486b5e84da4c…
Force block
— not fired
Score recovered
no
Elapsed
24.9s