CRX aminer
Extension icon

Dark Reader

Version 4.9.119 View in Chrome Web Store

Last scanned: about 13 hours ago

Extension Details

Developer: Dark Reader Ltd
Rating: 4.7 ★ (12.9K ratings)
Users: 6,000,000

Context-Aware Verdict

HIGH
Overall Risk
Trust Factors:

Dark Reader is a well-established extension with exceptional user adoption (6 million users) and strong ratings (4.7/5 stars from 12.9K reviews). The extension is developed by Dark Reader Ltd, a legitimate company focused on this specific functionality. The high user base and positive ratings suggest the extension delivers on its promise of providing dark mode for websites.

Concerns:

The broad host permissions (*://*/*) and content script injection capabilities across all URLs present significant security exposure. While these permissions are technically necessary for Dark Reader to modify website appearance on any site, they create potential attack vectors if the extension were compromised. The storage permission, though standard for extensions that save user preferences, adds another data collection point. The extension's ability to access and modify content on all websites means it could theoretically intercept sensitive information like passwords or personal data.

Recommendations:

Given the extension's legitimate purpose and strong reputation, the risk is acceptable for most users who want dark mode functionality. However, security-conscious users should consider running it in a separate Chrome profile to isolate potential risks. Regularly review the extension's permissions and updates. For users handling highly sensitive data, consider using built-in browser dark modes or website-specific dark mode options when available instead of this broad-access extension.

Findings

HIGH
Broad Content Script Injection
This extension can inject scripts into any website. This means it could potentially read sensitive data, modify website content, or steal credentials.
HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.