Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Pac-Man Cursor - Custom Retro Cursor for Chrome

emekjhecncemhkpoolndbgmbgfieipdh
Risk Score
4.57
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Entertainment
Installs 108
Rating 3.0
Last updated 2026-06-28 (2 months ago)
Manifest version MV3
CSP present ❌ no
Developer info@tabplugins.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Uninstall + install URL hijack to tabplugins.com affiliate/upsell pages — traffic monetization pattern.
  • scripting + *://*/* gives JS injection capability over every site the user visits.
  • No CSP (MV3): dom_sink_innerhtml_userctrl finding is unmitigated XSS risk.
  • Privacy policy admits data collection and third-party sharing without retention disclosure.
  • Tiny install base (108) with HIGH-tier permissions — tail attack surface anomaly.

Evidence

  • uninstall_url_hijack manifest setUninstallURL to tabplugins.com/cursors/ with UTM params — classic traffic monetization.
  • install_url_hijack manifest onInstalled opens tabplugins.com/pac-man-cursor/ with UTM params — monetization on install.
  • scripting + *://*/* manifest Broad scripting permission plus all-URL host access enables JS injection on every page.
  • dom_sink_innerhtml_userctrl crx innerHTML sink in main.4964ab1e.js with no CSP; DOM-XSS vector unmitigated.
  • privacy_policy_classification api Policy scoped but admits data collection + third-party sharing; retention not disclosed.
  • install_perm_anomaly api 108 installs with HIGH-tier permissions (scripting + *://*/*) — small install, high perm.
  • csp_absent_mv3 manifest content_security_policy is null; no explicit CSP defined for MV3 extension.
  • reputation store Not verified publisher, not featured; dev 'WallExt' at tabplugins.com, unconfirmed org.

Permissions Breakdown

  • storage low Standard local state persistence; low risk alone.
  • unlimitedStorage low Extends storage quota; minimal additional risk.
  • scripting high Enables programmatic JS injection into pages; high capability when paired with *://*/*.
  • *://*/* (host_permissions) high Broad host access on every URL; amplifies scripting and content_scripts reach.
  • *://*/* (content_scripts) high Content script runs on every page the user visits; large attack surface.

Pillar Scores

Permissions6.00
Reputation5.50
Network2.00
Webstore8.00
Maintenance0.00
Privacy2.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 09:57
Listing SHA a7e3bca9679f…
Force block — not fired
Score recovered no
Elapsed