Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Winnie The Pooh Cursor ★ Custom Cursor for Chrome™

gdnhbhfhnjcfhakagfdeeblhnpjcfjnn
Risk Score
4.78
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Entertainment
Installs 519
Rating 5.0
Last updated 2025-11-30 (9 months ago)
Manifest version MV3
CSP present ❌ no
Developer gunaysimge48@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Uninstall URL hijack redirects to yowgames.com with UTM tracking — monetization signal.
  • Install URL hijack opens yowgames.com on first install — unsolicited redirect.
  • Privacy policy covers yowgames.com generically; admits data collection + 3rd-party sharing, no extension scope.
  • Free-webmail developer (gunaysimge48@gmail.com) with no verified business identity.
  • Content script on all URLs grants page-read capability on every site user visits.

Evidence

  • uninstall_url_hijack crx setUninstallURL points to yowgames.com with UTM params — 3rd-party monetization redirect.
  • install_url_hijack crx onInstalled opens yowgames.com with UTM tracking params on every fresh install.
  • privacy_policy_generic store Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true — D clause applies: +10.0.
  • free_webmail_developer store Developer email gunaysimge48@gmail.com with no verified publisher or business domain.
  • content_scripts_broad manifest content_scripts_matches=[*://*/*] injects into every page despite cursor-only stated function.
  • js_external_hosts crx External JS hosts: chrome.google.com, yowgames.com — yowgames is operator's own domain.
  • operator_cluster_zero_siblings api sibling_count=0; no broader cluster detected under this fingerprint.
  • cve_findings_empty crx jquery 3.6.0 bundled; no CVEs found in cve_findings_raw.

Permissions Breakdown

  • storage low Stores cursor preferences locally; standard for theme extensions.
  • content_scripts *://*/* medium Runs on every page visited; broader than needed for a cursor extension.

Pillar Scores

Permissions1.30
Reputation6.50
Network2.00
Webstore8.00
Maintenance3.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 10:07
Listing SHA ee9bc20bb43a…
Force block — not fired
Score recovered no
Elapsed