Futurama Cursor - Custom Cartoon Cursor for Chrome
dnfjhcohapaoibiekobphekeohdamjbi
Risk Score
6.07
Risk Level:
High
Recommendation:
🚫 BLOCK
Top Risks
- Uninstall URL hijack redirects to tabplugins.com — monetization shell pattern confirmed.
- Install URL hijack opens tabplugins.com on install — aggressive traffic monetization.
- Privacy policy is Google's generic policy, not scoped to this extension; admits data collection and 3rd-party sharing.
- Free-webmail developer (heroking15@gmail.com) with no verified business identity; no verified publisher badge.
- scripting + *://*/*HostPermission grants full page-script injection across all sites with only 33 installs.
Evidence
- uninstall_url_hijack crx chrome.runtime.setUninstallURL → https://tabplugins.com/cursors/ (3rd-party monetization site).
- install_url_hijack crx onInstalled opens https://tabplugins.com/hunter-x-hunter-cursor/ — traffic-monetization redirect.
- generic_privacy_policy store Policy URL is Google's own account privacy page; scope_extension=false, admits data collection+3rd-party sharing.
- free_webmail_developer store Developer email heroking15@gmail.com; no verified publisher; no business domain.
- broad_host_permissions manifest host_permissions: *://*/* paired with scripting — full page injection capability on all sites.
- dom_sink_innerhtml crx dom_sink_innerhtml_userctrl in main.4964ab1e.js; no CSP present, raising XSS risk.
- js_external_hosts crx Extension references tabplugins.com, reactjs.org, chrome.google.com externally.
- small_install_high_perm api Only 33 installs with HIGH-tier permissions (scripting + *://*/*) — tail attack surface anomaly.
Permissions Breakdown
- storage low Stores cursor preferences locally; low risk on its own.
- unlimitedStorage low Expands storage quota; minor risk for cursor asset caching.
- scripting high Allows programmatic script injection into any page via *://*/*HostPerms.
- *://*/*HostPermission high Broad host access; scripting+all_urls enables reading/modifying every page.
Pillar Scores
Permissions6.50
Reputation7.50
Network2.00
Webstore8.00
Maintenance1.50
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 09:50
Listing SHA
a70680939aa6…
Force block
— not fired
Score recovered
no
Elapsed
—