Black Clover Cursor - Custom Anime Cursor for Chrome
bjacehmkdjdpknkoomphgfheehjfiocg
Risk Score
4.44
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Uninstall and install URL hijack redirect users to tabplugins.com marketing pages — classic monetization shell signal.
- broad host access (*://*/*) + scripting on all sites for a trivial cursor extension — disproportionate capability.
- Privacy policy discloses data collection and third-party sharing but lacks retention details; inadequate for scope.
- No developer name listed; missing last_updated date limits accountability and maintenance assessment.
- Small install base (596) with HIGH-tier permissions flags tail-attack-surface risk.
Evidence
- install_url_hijack + uninstall_url_hijack manifest Both onInstalled and uninstall URLs redirect to tabplugins.com marketing pages — monetization shell pattern.
- broad host permissions manifest host_permissions *://*/* + content_scripts_matches *://*/* grant access to every page visited.
- dom_sink_innerhtml_userctrl crx innerHTML sink found in main.4964ab1e.js; csp_present==false amplifies DOM-XSS risk.
- privacy_policy_classification api Policy fetched; scope_extension=true, data_collection=true, retention=false, third_party_sharing=true.
- verified_publisher store tabplugins.com is a verified publisher, capping reputation discount per v3.5 rules.
- install_perm_anomaly api 596 installs with HIGH-tier permissions flagged small_install_high_perm=true.
- no developer_name store developer_name field is empty; reduces accountability signal.
- months_since_update null store last_updated missing; maintenance pillar scored conservatively at 3-6 month band.
Permissions Breakdown
- storage low Local preference storage; low risk for a cursor extension.
- unlimitedStorage low Extended storage quota; minimal additional risk beyond storage.
- scripting medium Allows injecting scripts into pages; elevated when paired with *://*/* host access.
- *://*/* (host_permissions) high Broad host access across all sites; combined with scripting raises capability significantly.
- *://*/* (content_scripts_matches) high Content script runs on every page; doubles broad-access risk surface.
Pillar Scores
Permissions5.50
Reputation4.00
Network2.00
Webstore7.50
Maintenance3.50
Privacy2.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 09:34
Listing SHA
8eff6cc7efae…
Force block
— not fired
Score recovered
no
Elapsed
—