Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Cute Cursors - Custom Cursor for Chrome™

anflghppebdhjipndogapfagemgnlblh
Risk Score
4.04
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Entertainment
Installs 800,000
Rating 4.6
Last updated 2026-03-24 (6 months ago)
Manifest version MV3
CSP present ❌ no
Developer thanhkinestan@gmail.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • <all_urls> + scripting: can inject JS into every page; high-value target if extension is ever compromised or sold.
  • Privacy policy does not scope to this extension, discloses no data collection details — inadequate for 800K users.
  • Developer identity is a free Gmail account with no verified business website; accountability gap.
  • tabs permission exposes full browsing history metadata beyond cursor-display needs.
  • No CSP declared (MV3 default applies, but absence of explicit policy is noted alongside broad host access).

Evidence

  • verified_publisher + featured store Extension carries both verified-publisher badge and Google Featured badge, partially mitigating identity risk.
  • broad_host_access_with_scripting manifest host_permissions:<all_urls> + scripting permission enables JS injection on every website user visits.
  • gmail_developer_email store Developer email thanhkinestan@gmail.com is free webmail; no verified business domain or developer name supplied.
  • privacy_policy_inadequate api Policy fetched (1613 chars); scope_extension=false, data_collection=false, retention=false — too generic/short to be adequate.
  • no_code_findings crx 5 JS files scanned; obfuscation_score=0.0; no malicious patterns detected in code_findings_raw.
  • no_cve_findings crx cve_findings_raw is empty; no vulnerable bundled libraries detected.
  • no_threat_intel_hits api bad_host_hits, monetization_hits, affiliate_hits all empty; no known-bad network destinations.
  • maintenance_3_to_6_months store months_since_update=5; falls in 3-6 month band (+1.5 maintenance score).

Permissions Breakdown

  • storage low Stores cursor preferences locally; expected for this category.
  • unlimitedStorage low Stores cursor asset packs; reasonable for a cursor customizer.
  • tabs medium Grants access to tab URLs and titles; broader than strictly needed for cursor injection.
  • activeTab low Limits scripting to the currently active tab on user gesture.
  • scripting medium Enables programmatic script injection into pages; paired with <all_urls> increases reach.
  • <all_urls> (host_permission) high Combined with scripting, allows JS injection into every page the user visits.

Pillar Scores

Permissions5.80
Reputation3.50
Network2.00
Webstore1.50
Maintenance1.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Scoring History

sssiedn4cd927afdp727562726963xsx 3.78 Low review 2026-09-05
sssiednb1a53fbddp727562726963xsx 3.55 Low review 2026-08-30
v3.6 4.04 Medium review 2026-08-28

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 07:48
Listing SHA 0d79c4f7f15b…
Force block — not fired
Score recovered no
Elapsed