The extension comes from chromethemer.com, which appears to be a legitimate website focused on Chrome themes and extensions. With 1,000 users and a solid 4.6-star rating from 19 reviews, it shows reasonable user satisfaction. The extension's purpose as a Christmas-themed decorative add-on is straightforward and matches user expectations for seasonal browser customization.
The primary concern is the use of Manifest Version 2, which has weaker security controls compared to the newer Manifest V3 standard. This older framework provides extensions with broader access capabilities and fewer restrictions on potentially risky operations. However, the extension appears to request minimal permissions, which significantly reduces the security risk despite the older manifest version.
The relatively small user base of 1,000 users means less community vetting compared to more popular extensions, though this is typical for seasonal or niche extensions.
This extension poses minimal security risk for typical users due to its limited permissions and straightforward functionality. You can safely install it in your main browser profile. However, keep an eye out for updates that might migrate to Manifest V3 for enhanced security. Consider removing the extension after the holiday season if you no longer need the Christmas lights decoration, as this reduces your overall extension attack surface.
| https://clients2.google.com/service/update2/crx |
{ "name": "Christmas Lights", "icons": { "128": "icon128.png" }, "theme": { "tints": { "frame": [ 255.0, 255.0, 0.44 ], "buttons": [ 1.0, 1.0, 1.0 ], "background_tab": [ -1.0, 0.5, 0.75 ], "frame_inactive": [ -1.0, 0.3, 0.6 ], "frame_incognito": [ -1.0, 0.2, 0.35 ], "frame_incognito_inactive": [ -1.0, 0.3, 0.6 ] }, "colors": { "frame": [ 6, 6, 6 ], "toolbar": [ 6, 6, 6 ], "ntp_link": [ 33, 33, 33 ], "ntp_text": [ 255, 255, 255 ], "tab_text": [ 255, 255, 255 ], "ntp_header": [ 0, 0, 0 ], "ntp_section": [ 74, 74, 74 ], "bookmark_text": [ 150, 214, 89 ], "frame_inactive": [ 71, 71, 71 ], "ntp_background": [ 1, 0, 0 ], "frame_incognito": [ 0, 0, 0 ], "ntp_section_link": [ 33, 33, 33 ], "ntp_section_text": [ 45, 45, 45 ], "button_background": [ 6, 6, 6 ], "control_background": [ 211, 211, 211 ], "ntp_link_underline": [ 45, 45, 45 ], "tab_background_text": [ 127, 240, 254 ], "frame_incognito_inactive": [ 71, 71, 71 ], "ntp_section_link_underline": [ 74, 74, 74 ] }, "images": { "theme_frame": "images/theme_frame.png", "theme_toolbar": "images/theme_toolbar.png", "theme_ntp_background": "images/theme_ntp_background.png", "theme_tab_background": "images/theme_tab_background.png", "theme_button_background": "images/theme_button_background.png" }, "properties": { "ntp_logo_alternate": 2, "ntp_background_repeat": "repeat-x", "ntp_background_alignment": "fit" } }, "version": "1.0", "short_name": "Christmas Lights", "update_url": "https://clients2.google.com/service/update2/crx", "description": "__MSG_appDesc__", "default_locale": "en", "manifest_version": 2 }
ⓘ CRXaminer has partnered with our friends at Secure Annex to provide additional findings unique to their platform.
Secure Annex also analyzes extensions from other browsers, IDEs, and can continuously monitor.
This extension may not yet be analyzed by Secure Annex.