Peanuts Cursor ★ Custom Cursor for Chrome™
eenfkghojihnhnninifhndjilpibchki
Risk Score
4.74
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Uninstall and install URL hijacks redirect to yowgames.com with UTM tracking — monetization shell pattern.
- Privacy policy is generic yowgames.com policy: not scoped to this extension, but admits data collection and third-party sharing — worst-case privacy signal.
- Content scripts injected on all URLs (*://*/*) from a free-webmail developer with no verified identity.
- Developer uses free Gmail address with no verified publisher badge; developer_name differs from email identity.
- No CSP declared (MV3 default applies) but content scripts run on every site with a broad-reach cursor.
Evidence
- uninstall_url_hijack manifest setUninstallURL → yowgames.com with UTM params; classic monetization shell indicator.
- install_url_hijack manifest onInstalled opens yowgames.com with UTM params — install redirect to 3rd-party site.
- privacy_policy_generic_with_data_collection api Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy.
- free_webmail_developer store Developer email busrakaraman256@gmail.com; no verified publisher; developer_name=wallpaperlive.
- content_scripts_all_urls manifest content_scripts_matches=[*://*/*] — scripts injected on every page for a cursor cosmetic.
- js_external_hosts crx External JS hosts: chrome.google.com, yowgames.com — yowgames is operator's own domain.
- no_cve_findings crx jquery 3.6.0 bundled; cve_findings_raw empty — no known CVEs at this version.
- operator_cluster_singleton api sibling_count=0; no cluster detected. Install+uninstall hijack fingerprint unique to this extension.
Permissions Breakdown
- storage low Used to save cursor preference settings locally.
- content_scripts *://*/* high Injects scripts on every page the user visits; broad reach for a cursor extension.
Pillar Scores
Permissions2.30
Reputation6.50
Network2.00
Webstore7.00
Maintenance3.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 09:53
Listing SHA
0ac894a266a8…
Force block
— not fired
Score recovered
no
Elapsed
—