Cute Cursors - Custom Cursor for Chrome™
anflghppebdhjipndogapfagemgnlblh
Risk Score
4.04
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- <all_urls> + scripting: can inject JS into every page; high-value target if extension is ever compromised or sold.
- Privacy policy does not scope to this extension, discloses no data collection details — inadequate for 800K users.
- Developer identity is a free Gmail account with no verified business website; accountability gap.
- tabs permission exposes full browsing history metadata beyond cursor-display needs.
- No CSP declared (MV3 default applies, but absence of explicit policy is noted alongside broad host access).
Evidence
- verified_publisher + featured store Extension carries both verified-publisher badge and Google Featured badge, partially mitigating identity risk.
- broad_host_access_with_scripting manifest host_permissions:<all_urls> + scripting permission enables JS injection on every website user visits.
- gmail_developer_email store Developer email thanhkinestan@gmail.com is free webmail; no verified business domain or developer name supplied.
- privacy_policy_inadequate api Policy fetched (1613 chars); scope_extension=false, data_collection=false, retention=false — too generic/short to be adequate.
- no_code_findings crx 5 JS files scanned; obfuscation_score=0.0; no malicious patterns detected in code_findings_raw.
- no_cve_findings crx cve_findings_raw is empty; no vulnerable bundled libraries detected.
- no_threat_intel_hits api bad_host_hits, monetization_hits, affiliate_hits all empty; no known-bad network destinations.
- maintenance_3_to_6_months store months_since_update=5; falls in 3-6 month band (+1.5 maintenance score).
Permissions Breakdown
- storage low Stores cursor preferences locally; expected for this category.
- unlimitedStorage low Stores cursor asset packs; reasonable for a cursor customizer.
- tabs medium Grants access to tab URLs and titles; broader than strictly needed for cursor injection.
- activeTab low Limits scripting to the currently active tab on user gesture.
- scripting medium Enables programmatic script injection into pages; paired with <all_urls> increases reach.
- <all_urls> (host_permission) high Combined with scripting, allows JS injection into every page the user visits.
Pillar Scores
Permissions5.80
Reputation3.50
Network2.00
Webstore1.50
Maintenance1.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Scoring History
| sssiedn4cd927afdp727562726963xsx | 3.78 | Low | review | 2026-09-05 |
| sssiednb1a53fbddp727562726963xsx | 3.55 | Low | review | 2026-08-30 |
| v3.6 | 4.04 | Medium | review | 2026-08-28 |
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 07:48
Listing SHA
0d79c4f7f15b…
Force block
— not fired
Score recovered
no
Elapsed
—