Winnie The Pooh Cursor ★ Custom Cursor for Chrome™
gdnhbhfhnjcfhakagfdeeblhnpjcfjnn
Risk Score
4.78
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Uninstall URL hijack redirects to yowgames.com with UTM tracking — monetization signal.
- Install URL hijack opens yowgames.com on first install — unsolicited redirect.
- Privacy policy covers yowgames.com generically; admits data collection + 3rd-party sharing, no extension scope.
- Free-webmail developer (gunaysimge48@gmail.com) with no verified business identity.
- Content script on all URLs grants page-read capability on every site user visits.
Evidence
- uninstall_url_hijack crx setUninstallURL points to yowgames.com with UTM params — 3rd-party monetization redirect.
- install_url_hijack crx onInstalled opens yowgames.com with UTM tracking params on every fresh install.
- privacy_policy_generic store Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true — D clause applies: +10.0.
- free_webmail_developer store Developer email gunaysimge48@gmail.com with no verified publisher or business domain.
- content_scripts_broad manifest content_scripts_matches=[*://*/*] injects into every page despite cursor-only stated function.
- js_external_hosts crx External JS hosts: chrome.google.com, yowgames.com — yowgames is operator's own domain.
- operator_cluster_zero_siblings api sibling_count=0; no broader cluster detected under this fingerprint.
- cve_findings_empty crx jquery 3.6.0 bundled; no CVEs found in cve_findings_raw.
Permissions Breakdown
- storage low Stores cursor preferences locally; standard for theme extensions.
- content_scripts *://*/* medium Runs on every page visited; broader than needed for a cursor extension.
Pillar Scores
Permissions1.30
Reputation6.50
Network2.00
Webstore8.00
Maintenance3.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 10:07
Listing SHA
ee9bc20bb43a…
Force block
— not fired
Score recovered
no
Elapsed
—