Night Sun - Easy Dark Mode
ogcoelhdhiklkfpdnbknmgeaakhghjkg
Risk Score
3.53
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- scripting + <all_urls> allows injection into every page the user visits.
- Uninstall and install URL hijack redirect to gameograf.com — monetization/tracking signal.
- No developer name listed on store; reduced accountability.
- 13 months since last update — limited maintenance signal.
- Verified publisher discount partially offset by uninstall/install URL hijack pattern.
Evidence
- broad_host_scripting manifest scripting + <all_urls> host permission enables JS injection into every site; justified for dark mode but high capability.
- uninstall_url_hijack crx chrome.runtime.setUninstallURL points to https://gameograf.com — developer-controlled but is a monetization/tracking pattern.
- install_url_hijack crx onInstalled opens https://gameograf.com — developer-controlled redirect on install.
- verified_publisher store Extension carries verified publisher badge; reduces reputation risk but does not negate hijack patterns.
- no_developer_name store developer_name is empty string; reduces accountability signal.
- privacy_policy_adequate api Policy fetched; scope_extension=true, data_collection=true, retention=true, third_party_sharing=true — fully disclosed.
- tail_attack_surface api install_perm_anomaly.tail_attack_surface=true: 3,000 installs with HIGH-tier permissions.
- clean_code_scan crx 4 JS files scanned; code_findings_raw empty, obfuscation_score=0.0, no CVEs, no bad host hits.
Permissions Breakdown
- storage low Stores user preferences (dark mode settings); low impact.
- tabs medium Access to tab URLs and metadata; paired with <all_urls> elevates reach.
- scripting high Programmatic script injection into any page via <all_urls>; broad capability.
- activeTab low Redundant with scripting+<all_urls> but nominally limited to active tab.
- <all_urls> (host_permission) high Grants access to every site visited; combined with scripting = full page control.
Pillar Scores
Permissions5.50
Reputation4.00
Network0.00
Webstore5.50
Maintenance6.00
Privacy0.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-01 05:38
Listing SHA
292f728a6d9d…
Force block
— not fired
Score recovered
no
Elapsed
—