Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Peanuts Cursor ★ Custom Cursor for Chrome™

eenfkghojihnhnninifhndjilpibchki
Risk Score
4.74
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Entertainment
Installs 1,000
Rating 5.0
Last updated 2025-12-08 (8 months ago)
Manifest version MV3
CSP present ❌ no
Developer busrakaraman256@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Uninstall and install URL hijacks redirect to yowgames.com with UTM tracking — monetization shell pattern.
  • Privacy policy is generic yowgames.com policy: not scoped to this extension, but admits data collection and third-party sharing — worst-case privacy signal.
  • Content scripts injected on all URLs (*://*/*) from a free-webmail developer with no verified identity.
  • Developer uses free Gmail address with no verified publisher badge; developer_name differs from email identity.
  • No CSP declared (MV3 default applies) but content scripts run on every site with a broad-reach cursor.

Evidence

  • uninstall_url_hijack manifest setUninstallURL → yowgames.com with UTM params; classic monetization shell indicator.
  • install_url_hijack manifest onInstalled opens yowgames.com with UTM params — install redirect to 3rd-party site.
  • privacy_policy_generic_with_data_collection api Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy.
  • free_webmail_developer store Developer email busrakaraman256@gmail.com; no verified publisher; developer_name=wallpaperlive.
  • content_scripts_all_urls manifest content_scripts_matches=[*://*/*] — scripts injected on every page for a cursor cosmetic.
  • js_external_hosts crx External JS hosts: chrome.google.com, yowgames.com — yowgames is operator's own domain.
  • no_cve_findings crx jquery 3.6.0 bundled; cve_findings_raw empty — no known CVEs at this version.
  • operator_cluster_singleton api sibling_count=0; no cluster detected. Install+uninstall hijack fingerprint unique to this extension.

Permissions Breakdown

  • storage low Used to save cursor preference settings locally.
  • content_scripts *://*/* high Injects scripts on every page the user visits; broad reach for a cursor extension.

Pillar Scores

Permissions2.30
Reputation6.50
Network2.00
Webstore7.00
Maintenance3.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 09:53
Listing SHA 0ac894a266a8…
Force block — not fired
Score recovered no
Elapsed