One Piece Cursor - Custom Anime Cursor for Chrome
bhcjjbencodlgfoneipfnnpclempbdka
Risk Score
4.41
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Uninstall URL hijack to tabplugins.com ad/referral page — confirmed traffic monetization on removal.
- Install URL hijack — opens 3rd-party marketing URL on install, classic monetization shell pattern.
- broad host access (*://*/*) + scripting on an Entertainment cursor extension with no CSP — high-reach code injection surface.
- Privacy policy discloses third-party data sharing but lacks retention period; data collection scope confirmed.
- No ratings/reviews and very low install count (511) with HIGH-tier permissions — tail-attack-surface anomaly.
Evidence
- uninstall_url_hijack manifest setUninstallURL → tabplugins.com/cursors/ with UTM tracking; +3.0 Webstore.
- install_url_hijack manifest onInstalled opens tabplugins.com/one-piece-cursor/ with UTM params; +2.0 Webstore.
- broad_host_access manifest host_permissions *://*/* + content_scripts *://*/* grants access to every page visited.
- no_csp crx csp_present=false; MV3 default is strict but no explicit CSP; amplifies innerHTML finding.
- dom_sink_innerhtml crx innerHTML assignment found in main.4964ab1e.js — DOM-XSS risk surface.
- privacy_policy_third_party_sharing api Policy fetched, scope_extension=true, data_collection=true, third_party_sharing=true, retention=false.
- install_perm_anomaly store 511 installs + has_high_tier_permission=true → small_install_high_perm anomaly flagged.
- no_verified_publisher store verified_publisher=false, is_featured=false, rating=0 across 0 reviews; dev=WallExt/tabplugins.com.
Permissions Breakdown
- storage low Stores cursor preferences locally; low risk.
- unlimitedStorage low Allows large local storage; low standalone risk.
- scripting medium Enables programmatic script injection into pages; elevated when paired with broad host access.
- *://*/* high Broad host access covering all URLs; grants read/write capability on every visited site.
Pillar Scores
Permissions6.50
Reputation5.00
Network2.00
Webstore7.50
Maintenance0.00
Privacy2.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 09:32
Listing SHA
11ab5ffc435d…
Force block
— not fired
Score recovered
no
Elapsed
—