Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Bleach Cursor - Custom Anime Cursor for Chrome

cckgnbinkelflpimkpadlfmlpbbagmka
Risk Score
4.34
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Entertainment
Installs 423
Rating
Last updated 2026-06-21 (2 months ago)
Manifest version MV3
CSP present ❌ no
Developer info@tabplugins.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • scripting + *://*/* grants full DOM read/write on every site; cursor extension doesn't need this breadth.
  • Uninstall URL hijack redirects to tabplugins.com ad/referral page — monetization shell pattern.
  • Install URL hijack opens tabplugins.com referral page on install — unsolicited redirect.
  • Privacy policy admits data collection and third-party sharing without scoping to this extension.
  • No developer name listed; small-install + HIGH-perm anomaly flags tail-attack-surface risk.

Evidence

  • broad_host_scripting manifest scripting + host *://*/* enables code injection on all sites; unjustified for a cursor reskin.
  • uninstall_url_hijack crx setUninstallURL → https://tabplugins.com/cursors/?utm_source=google&utm_medium=referral&...
  • install_url_hijack crx onInstalled opens https://tabplugins.com/bleach-cursor-.../?utm_source=google&utm_medium=referral
  • privacy_policy_third_party_sharing api Policy fetched; scope_extension=true but data_collection=true, third_party_sharing=true, retention=false.
  • small_install_high_perm api 423 installs with HIGH-tier permission (scripting + all_urls) — tail-attack-surface anomaly.
  • dom_sink_innerhtml crx innerHTML assignment in main.4964ab1e.js; no CSP present, elevating XSS sink risk.
  • no_developer_name store developer_name is empty string; reduces accountability signal.
  • verified_publisher store verified_publisher=true on tabplugins.com; resolves, not throwaway — partial trust offset.

Permissions Breakdown

  • storage low Standard local state storage; low risk alone.
  • unlimitedStorage low Extends storage quota; minimal additional risk.
  • scripting high Allows dynamic script injection into pages; paired with *://*/* = full DOM access.
  • *://*/* high Broad host permission — scripting runs on every site user visits.

Pillar Scores

Permissions6.50
Reputation4.00
Network2.00
Webstore7.50
Maintenance0.00
Privacy2.00
Code Quality2.50
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 09:38
Listing SHA 67da8bd10bae…
Force block — not fired
Score recovered no
Elapsed