Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Kirby Cursor Cursor for Chrome

dnhfbehomlbkmimmmoejcmcondhmebia
Risk Score
3.38
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category Other
Installs 1,000
Rating 1.0
Last updated 2026-06-18 (2 months ago)
Manifest version MV3
CSP present ❌ no
Developer info@tabplugins.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Uninstall URL hijack routes users to operator ad/upsell page on every uninstall.
  • Install URL hijack opens 3rd-party marketing page on every install.
  • scripting + *://*/* grants universal JS injection on all sites visited.
  • Privacy policy admits data collection & 3rd-party sharing without retention disclosure.
  • No developer name; rating of 1/5 signals poor user trust for a cursor-only extension.

Evidence

  • uninstall_url_hijack manifest setUninstallURL → tabplugins.com/cursors/?utm_source=google; monetization/tracking redirect on uninstall.
  • install_url_hijack manifest onInstalled opens tabplugins.com/kirby-cursor/?utm_source=google; affiliate/traffic harvesting on install.
  • broad_host_scripting manifest scripting + host_permissions *://*/* allows JS injection on every site.
  • privacy_policy_inadequate store Policy fetched; scope_extension=true, data_collection=true, third_party_sharing=true, retention=false.
  • dom_sink_innerhtml crx innerHTML assigned from variable in main.4964ab1e.js — DOM-XSS risk.
  • no_csp manifest content_security_policy is null; csp_present=false on MV3 extension.
  • low_rating store Rating 1/5 — worst possible score for a 1,000-install cursor extension.
  • no_developer_name store developer_name is empty string; reduced accountability.

Permissions Breakdown

  • storage low Local state only; low capability on its own.
  • unlimitedStorage low Extends storage quota; no direct data-exfil risk.
  • scripting high Combined with *://*/* host access: can inject JS into every page.
  • *://*/* (host_permissions) high Broad host access amplifies scripting to universal page control.

Pillar Scores

Permissions6.00
Reputation5.50
Network2.00
Webstore6.50
Maintenance0.00
Privacy2.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 09:50
Listing SHA 9e5edc0cfc08…
Force block — not fired
Score recovered no
Elapsed