Firefox Add-ons

Dark Reader

by Dark Reader Ltd · 1.3M users · 4.5 rating
ccfa5806-8c88-51f4-a38a-14d0f6af76d3 | v4.9.133
60/ 100
MEDIUM risk
No change since v4.9.131
Analyst verdict
Confirmed risk

From the RiskyPlugins AI security review of the observed evidence.

Analysis record

Analysed
1 weeks ago
Version
v4.9.133
Artifact
SHA256 EB0…3AB
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

10 detail rows

Publisher Evidence

Limited evidence

Dark Reader Ltd

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

Firefox does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.

62
Noisy-finding weight
x1.00
Publisher domain
darkreader.org
Observed
Store verification signal
Limited signal
Limited
Extension portfolio
2
Portfolio

12 evidence rows available.

Finding Categories

8
Network

Requested Permissions

6 permissions
<all_urls>

Access and modify data on every website you visit

Dangerous
tabs
Medium
alarms
Low
contextMenus
Low
storage
Low
theme
Low

AI Security Report

AI Security Review

Evidence context: threat category typosquatting; evidence quality moderate.

This extension presents a significant typosquatting concern. The name "Dark Reader" exactly matches a well-established, popular dark mode extension that is legitimately published by Dark Reader Ltd with millions of users across browser stores. However, this listing shows an empty developer name field, which is inconsistent with the legitimate Dark Reader extension that clearly attributes its developer.

The extension requests manifest permissions including 'tabs' and '' in manifest.json, which are technically necessary for a dark mode extension to function but also enable broad browser access. Eight network findings were detected across background/index.js and inject/index.js, including fetch calls at lines 4572, 3734, 3647, 3696, 3185, 7226, 3626, and 3123, plus one xmlhttprequest call. However, these findings do not identify specific destination domains—they only flag the presence of network activity, which is expected for any extension that may fetch configuration or updates.

Critically, there are zero malware signatures, zero obfuscation findings, and zero suspicious IoC domains in the evidence. The extension has 1,315,269 users on Firefox, which could indicate either legitimate adoption or successful impersonation that has gained traction over time.

The strongest counterargument to this verdict is the absence of confirmed malicious behavior. No suspicious domains appear in the network findings, no malware signatures matched, and the code shows no obfuscation. A skeptic could argue this is simply a legitimate Dark Reader variant where developer attribution was not properly captured in the store metadata. However, the exact name match combined with missing developer information on a well-known extension is a documented typosquatting pattern. The legitimate Dark Reader has clear developer attribution, making this listing anomalous.

Recommendation: This requires verification of the publisher's identity. If this is not the legitimate Dark Reader, it should be flagged as impersonation regardless of whether malicious behavior has been detected, as the deception itself poses a risk to users who expect the trusted extension.

Key Reasons

  • Exact name match to well-known legitimate extension Dark Reader
  • Empty developer name field inconsistent with legitimate Dark Reader attribution
  • High user count (1.3M) without developer verification
  • No malware signatures or suspicious domains detected

False Positive Considerations

  • Generic network findings without domain specificity
  • Manifest permissions expected for dark mode functionality

Reviewed 2026-05-23; recommended action: escalate; model confidence 75%.

Firefox version history

Risk trend by version

9 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
60
Change since first
-3
Change from previous
No change
Versions:
First analyzed version
4.9.119
Jan 18, 2026
Risk range
60 to 63
Across analyzed versions
Latest analyzed version
4.9.133
Sep 24, 2026
Selected version
medium
Version
v4.9.133
1 weeks ago
Risk score
60
Findings
10
Change vs previous
No change

Pick any point on the chart to explore that version's code below.

About This Extension

This eye-care extension enables night mode creating dark themes for websites on the fly. Dark Reader inverts bright colors making them high contrast and easy to read at night. You can adjust brightness, contrast, sepia filter, dark mode, font settings and ignore-list. Dark Reader doesn't show ads and doesn't send user's data anywhere. It is fully open-source <a href="https://prod.outgoing.prod.webservices.mozgcp.net/v1/2a8020ee7fe5fea69148ed86ae4a26da4fc907d75110066fa5b5d0416670e666/https%3A//github.com/darkreader/darkreader" rel="nofollow">https://github.com/darkreader/darkreader</a> Before you install disable similar extensions. Enjoy watching!

Frequently Asked Questions