CRX aminer

Starting analysis...

Extension icon

dark reader - dark mode for Chrome

Version 1.0.7 View in Chrome Web Store

Last scanned: about 2 months ago | force re-scan

Extension Details

Developer: https://darkreader.net/
Rating: 4.6 ★ (227 ratings)
Users: 60,000

Context-Aware Verdict

HIGH
Overall Risk
Trust Factors:

The extension has a solid user base of 60,000 users and maintains a good rating of 4.6 stars from 227 reviews, suggesting general user satisfaction. The developer website (darkreader.net) appears to be associated with the legitimate Dark Reader project, which is a well-known dark mode extension. However, the relatively low download count compared to the official Dark Reader extension (which has millions of users) raises some questions about authenticity.

Concerns:

The extension requests extremely broad permissions that are typical for dark mode extensions but create significant security exposure. The combination of all_urls host permissions with content script injection capabilities means this extension can read and modify content on every website you visit. While the tabs permission is somewhat justified for a dark mode extension to detect page changes, it adds another layer of potential privacy risk. The storage permission, though lower risk, allows the extension to persist data locally.

Recommendations:

Given the high-risk permission set, consider running this extension in a separate Chrome profile dedicated to non-sensitive browsing. Before installing, verify this is the official Dark Reader extension by checking if there's a more popular version available. Monitor the extension's behavior and consider alternatives with more limited permissions if available. If you must use this extension, avoid using it while accessing sensitive websites like banking or email services. Regularly review what data the extension might be collecting through Chrome's extension management settings.

Findings

HIGH
Broad Content Script Injection
This extension can inject scripts into any website. This means it could potentially read sensitive data, modify website content, or steal credentials.
HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: tabs
This extension has the tabs permission. Can access browser tab information and manipulate tabs. This could potentially be used maliciously to compromise security or privacy.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.