Bleach Cursor - Custom Anime Cursor for Chrome
cckgnbinkelflpimkpadlfmlpbbagmka
Risk Score
4.34
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- scripting + *://*/* grants full DOM read/write on every site; cursor extension doesn't need this breadth.
- Uninstall URL hijack redirects to tabplugins.com ad/referral page — monetization shell pattern.
- Install URL hijack opens tabplugins.com referral page on install — unsolicited redirect.
- Privacy policy admits data collection and third-party sharing without scoping to this extension.
- No developer name listed; small-install + HIGH-perm anomaly flags tail-attack-surface risk.
Evidence
- broad_host_scripting manifest scripting + host *://*/* enables code injection on all sites; unjustified for a cursor reskin.
- uninstall_url_hijack crx setUninstallURL → https://tabplugins.com/cursors/?utm_source=google&utm_medium=referral&...
- install_url_hijack crx onInstalled opens https://tabplugins.com/bleach-cursor-.../?utm_source=google&utm_medium=referral
- privacy_policy_third_party_sharing api Policy fetched; scope_extension=true but data_collection=true, third_party_sharing=true, retention=false.
- small_install_high_perm api 423 installs with HIGH-tier permission (scripting + all_urls) — tail-attack-surface anomaly.
- dom_sink_innerhtml crx innerHTML assignment in main.4964ab1e.js; no CSP present, elevating XSS sink risk.
- no_developer_name store developer_name is empty string; reduces accountability signal.
- verified_publisher store verified_publisher=true on tabplugins.com; resolves, not throwaway — partial trust offset.
Permissions Breakdown
- storage low Standard local state storage; low risk alone.
- unlimitedStorage low Extends storage quota; minimal additional risk.
- scripting high Allows dynamic script injection into pages; paired with *://*/* = full DOM access.
- *://*/* high Broad host permission — scripting runs on every site user visits.
Pillar Scores
Permissions6.50
Reputation4.00
Network2.00
Webstore7.50
Maintenance0.00
Privacy2.00
Code Quality2.50
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 09:38
Listing SHA
67da8bd10bae…
Force block
— not fired
Score recovered
no
Elapsed
—