Pac-Man Cursor - Custom Retro Cursor for Chrome
emekjhecncemhkpoolndbgmbgfieipdh
Risk Score
4.57
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Uninstall + install URL hijack to tabplugins.com affiliate/upsell pages — traffic monetization pattern.
- scripting + *://*/* gives JS injection capability over every site the user visits.
- No CSP (MV3): dom_sink_innerhtml_userctrl finding is unmitigated XSS risk.
- Privacy policy admits data collection and third-party sharing without retention disclosure.
- Tiny install base (108) with HIGH-tier permissions — tail attack surface anomaly.
Evidence
- uninstall_url_hijack manifest setUninstallURL to tabplugins.com/cursors/ with UTM params — classic traffic monetization.
- install_url_hijack manifest onInstalled opens tabplugins.com/pac-man-cursor/ with UTM params — monetization on install.
- scripting + *://*/* manifest Broad scripting permission plus all-URL host access enables JS injection on every page.
- dom_sink_innerhtml_userctrl crx innerHTML sink in main.4964ab1e.js with no CSP; DOM-XSS vector unmitigated.
- privacy_policy_classification api Policy scoped but admits data collection + third-party sharing; retention not disclosed.
- install_perm_anomaly api 108 installs with HIGH-tier permissions (scripting + *://*/*) — small install, high perm.
- csp_absent_mv3 manifest content_security_policy is null; no explicit CSP defined for MV3 extension.
- reputation store Not verified publisher, not featured; dev 'WallExt' at tabplugins.com, unconfirmed org.
Permissions Breakdown
- storage low Standard local state persistence; low risk alone.
- unlimitedStorage low Extends storage quota; minimal additional risk.
- scripting high Enables programmatic JS injection into pages; high capability when paired with *://*/*.
- *://*/* (host_permissions) high Broad host access on every URL; amplifies scripting and content_scripts reach.
- *://*/* (content_scripts) high Content script runs on every page the user visits; large attack surface.
Pillar Scores
Permissions6.00
Reputation5.50
Network2.00
Webstore8.00
Maintenance0.00
Privacy2.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 09:57
Listing SHA
a7e3bca9679f…
Force block
— not fired
Score recovered
no
Elapsed
—