Dogs Cursor - Custom Dog Cursor for Chrome
gmjibldihkpammmelmkiipjcgmhdcdmb
Risk Score
6.76
Risk Level:
High
Recommendation:
🚫 BLOCK
Top Risks
- Uninstall and install URL hijacks redirect to tabplugins.com — classic monetization shell pattern.
- No developer name; free-webmail email (gmail) with no business website raises identity accountability risk.
- Privacy policy is Google's generic account policy — does not scope to this extension; policy admits data collection and 3rd-party sharing.
- scripting + *://*/*HostPermission gives full page access across all sites; small install base with high-perm is a tail-attack-surface signal.
- DOM-XSS sink (innerHTML) present with no CSP; amplifies injection risk on every page.
Evidence
- uninstall_url_hijack manifest setUninstallURL → https://tabplugins.com/cursors/ (3rd-party monetization site).
- install_url_hijack manifest onInstalled opens https://tabplugins.com/dogs-cursor-custom-dog-cursor-for-chrome/.
- no_developer_name_free_webmail store developer_name is empty; email is waqasamjad1232@gmail.com — no verifiable business identity.
- generic_privacy_policy store Privacy policy is Google's own account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
- broad_host_scripting manifest scripting permission + host_permissions *://*/* + content_scripts on *://*/* — full-page access everywhere.
- dom_xss_sink_no_csp crx innerHTML user-controlled sink in main.4964ab1e.js; csp_present=false amplifies DOM-XSS risk.
- install_perm_anomaly api 696 installs with HIGH-tier permissions; small_install_high_perm=true, tail_attack_surface=true.
- tabplugins_external_host crx js_external_hosts includes tabplugins.com — same domain as both URL hijacks.
Permissions Breakdown
- storage low Standard local data persistence, low inherent risk.
- unlimitedStorage low Allows large local storage quota; no exfil risk alone.
- scripting high Programmatic script injection into pages; high capability when paired with *://*/*.
- *://*/*HostPermission high Broad host access across all URLs amplifies scripting and content_scripts risk.
Pillar Scores
Permissions7.50
Reputation8.00
Network2.00
Webstore8.00
Maintenance6.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 10:40
Listing SHA
7dafabc36715…
Force block
— not fired
Score recovered
no
Elapsed
—