Dark Mode — Night Reader & Blue Light Filter
pdpfhanekfkeijhemmfbnnjffiblgefi
Risk Score
4.74
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy is Google's generic account policy — zero scope to this extension, admits data collection and 3rd-party sharing (Privacy pillar max).
- Gmail developer with no verifiable business identity; <all_urls> broad host access across all pages.
- scripting + <all_urls> allows arbitrary JS injection on every site the user visits.
- No CSP declared (MV3 mitigates somewhat but adds no explicit isolation).
- Extension runs content scripts on all URLs with no policy accountability for what is observed.
Evidence
- privacy_policy_generic store Policy URL is Google's own account policy; scope_extension=false, data_collection=true, third_party_sharing=true — scores maximum privacy risk.
- free_webmail_developer store Developer email pricew216@gmail.com — free webmail, no verifiable business entity behind a <all_urls> extension.
- broad_host_permissions manifest <all_urls> in host_permissions AND content_scripts_matches; scripting permission enables injection on every site.
- is_featured_by_google store Google 'Featured' badge present; reduces reputation risk but does not justify absent scoped privacy policy.
- no_csp manifest content_security_policy is null; MV3 provides some defaults but no explicit CSP hardening.
- code_findings_clean crx code_findings_raw empty, obfuscation_score=0.0; no malicious code signals detected in 6 JS files.
- cve_findings_clean crx cve_findings_raw empty; no known-vulnerable libraries detected.
- maintenance_6_12mo store Last updated October 2025, 10 months ago; falls in 6-12 month band (+3.5 maintenance).
Permissions Breakdown
- activeTab low Scoped to user-initiated tab; low risk alone.
- storage low Local preference storage; standard for dark mode settings.
- unlimitedStorage low Extends storage quota; minor risk escalation.
- scripting medium Allows dynamic script injection; paired with <all_urls> raises capability.
- <all_urls> (host_permission) high Grants access to every site visited; broad reach for a dark-mode tool.
- <all_urls> (content_scripts) high Content script runs on every page; can read/modify all page content.
Pillar Scores
Permissions5.50
Reputation6.50
Network2.00
Webstore1.00
Maintenance3.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 07:45
Listing SHA
2c61578b0db8…
Force block
— not fired
Score recovered
no
Elapsed
—