CRX aminer
Extension icon

Dark Reader

Version 4.9.125 View in Chrome Web Store

Last scanned: about 13 hours ago

Extension Details

Developer: Dark Reader Ltd
Rating: 4.7 ★ (13.1K ratings)
Users: 7,000,000

Context-Aware Verdict

HIGH
Overall Risk
Trust Factors:

Dark Reader is a well-established extension with exceptional user adoption (7 million users) and strong ratings (4.7/5 from 13.1K reviews). The extension is developed by Dark Reader Ltd, a dedicated company, which adds credibility. The extension's purpose - providing dark mode for websites - is legitimate and widely appreciated by users.

Concerns:

The broad host permissions (*://*/*) and content script injection capabilities across all URLs present significant security risks. While these permissions are functionally necessary for a dark mode extension to modify website appearance, they create potential attack vectors. The extension can access and modify content on every website you visit, including sensitive pages like banking sites, email, and social media. The storage permission, while lower risk, allows data persistence that could be concerning if compromised.

Recommendations:

Given the extension's popularity and legitimate purpose, the risk is somewhat mitigated by its reputation. However, consider these precautions: Monitor for unusual behavior or performance issues that might indicate compromise. Regularly review which sites you allow the extension to access through Chrome's site settings. For maximum security with sensitive financial or work-related browsing, consider using a separate Chrome profile without this extension. The extension's benefits likely outweigh risks for most users, but security-conscious users should remain vigilant about its broad access capabilities.

Findings

HIGH
Broad Content Script Injection
This extension can inject scripts into any website. This means it could potentially read sensitive data, modify website content, or steal credentials.
HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.