Shade Dark Mode
mkeimkkbcndbdlfkbfhhlfgkilcfniic
Risk Score
5.57
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy is Google's generic account policy — not scoped to this extension, admits data collection and third-party sharing.
- scripting + <all_urls> allows arbitrary JS injection into every visited page.
- Gmail developer with no business identity; no domain-age signal; unverified publisher.
- Extension contacts 4 external hosts (GA, GitHub, npms.io, Google Fonts) with no CSP.
- 16 months since last update with broad host permissions still active.
Evidence
- host_permissions_all_urls manifest <all_urls> grants scripting access to every site the user visits.
- privacy_policy_generic_google store Policy is myaccount.google.com generic page; scope_extension=false, data_collection=true, third_party_sharing=true.
- free_webmail_developer store Developer email cherishago6062@gmail.com; no business domain; unverified publisher.
- no_csp crx content_security_policy is null; MV3 default applies but no explicit restriction on external calls.
- external_hosts crx Contacts fonts.googleapis.com, github.com, npms.io, www.google-analytics.com at runtime.
- google_analytics_telemetry api monetization_hits lists google-analytics.com; only telemetry tier, not adtech.
- maintenance_stale store Last updated Feb 2025; 16 months since update — in 6-12 month band.
- is_featured_by_google store Extension carries Google Featured badge, partially offsetting reputation risk.
Permissions Breakdown
- alarms low Schedules periodic tasks; minimal risk in isolation.
- contextMenus low Adds right-click menu items; low standalone risk.
- scripting medium Injects scripts into pages; paired with <all_urls> raises capability.
- storage low Stores extension settings locally; minimal risk.
- <all_urls> high Host permission covering every site; broad reach for script injection.
Pillar Scores
Permissions5.50
Reputation7.00
Network3.00
Webstore2.50
Maintenance6.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:56
Listing SHA
5ff1862ee386…
Force block
— not fired
Score recovered
no
Elapsed
19.4s