Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Night Sun - Easy Dark Mode

ogcoelhdhiklkfpdnbknmgeaakhghjkg
Risk Score
3.53
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category Accessibility
Installs 3,000
Rating 5.0
Last updated 2025-08-12 (13 months ago)
Manifest version MV3
CSP present ❌ no
Developer info@gameograf.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • scripting + <all_urls> allows injection into every page the user visits.
  • Uninstall and install URL hijack redirect to gameograf.com — monetization/tracking signal.
  • No developer name listed on store; reduced accountability.
  • 13 months since last update — limited maintenance signal.
  • Verified publisher discount partially offset by uninstall/install URL hijack pattern.

Evidence

  • broad_host_scripting manifest scripting + <all_urls> host permission enables JS injection into every site; justified for dark mode but high capability.
  • uninstall_url_hijack crx chrome.runtime.setUninstallURL points to https://gameograf.com — developer-controlled but is a monetization/tracking pattern.
  • install_url_hijack crx onInstalled opens https://gameograf.com — developer-controlled redirect on install.
  • verified_publisher store Extension carries verified publisher badge; reduces reputation risk but does not negate hijack patterns.
  • no_developer_name store developer_name is empty string; reduces accountability signal.
  • privacy_policy_adequate api Policy fetched; scope_extension=true, data_collection=true, retention=true, third_party_sharing=true — fully disclosed.
  • tail_attack_surface api install_perm_anomaly.tail_attack_surface=true: 3,000 installs with HIGH-tier permissions.
  • clean_code_scan crx 4 JS files scanned; code_findings_raw empty, obfuscation_score=0.0, no CVEs, no bad host hits.

Permissions Breakdown

  • storage low Stores user preferences (dark mode settings); low impact.
  • tabs medium Access to tab URLs and metadata; paired with <all_urls> elevates reach.
  • scripting high Programmatic script injection into any page via <all_urls>; broad capability.
  • activeTab low Redundant with scripting+<all_urls> but nominally limited to active tab.
  • <all_urls> (host_permission) high Grants access to every site visited; combined with scripting = full page control.

Pillar Scores

Permissions5.50
Reputation4.00
Network0.00
Webstore5.50
Maintenance6.00
Privacy0.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-01 05:38
Listing SHA 292f728a6d9d…
Force block — not fired
Score recovered no
Elapsed