This thread is for the (old) custom css version, which you can copy-paste into your obsidian.css
It’s pretty secure, because it’s only presentation stuff.
The plugin itself is over on a different thread and also only touches presentation stuff. However it does so via the javascript API, so theoretically I could change it in future to access all your notes (possibly more if I knew what I was doing ). If you are so inclined you can audit the code yourself on github, or you can choose to trust me.