Death Note Cursor - Custom Anime Cursor for Chrome
hdholjicmhinpjcbmigoffjedkiihlen
Risk Score
6.69
Risk Level:
High
Recommendation:
🚫 BLOCK
Top Risks
- Uninstall and install URL hijacks redirect to tabplugins.com — confirmed monetization shell pattern.
- Google's own privacy policy submitted as extension policy: admits data collection + 3rd-party sharing with no extension scope.
- scripting + *://*/* allows arbitrary JS injection on every site the user visits.
- Free-webmail dev (gmail), no developer name, no business website — unverifiable identity.
- Small-install + high-perm anomaly and install_perm_anomaly flags both raised; tail attack surface risk.
Evidence
- uninstall_url_hijack crx chrome.runtime.setUninstallURL → https://tabplugins.com/cursors/ (3rd-party redirect).
- install_url_hijack crx onInstalled opens https://tabplugins.com/death-note-cursor/ (3rd-party redirect).
- privacy_policy_generic store Policy is Google's account privacy page; scope_extension=false, data_collection=true, third_party_sharing=true.
- free_webmail_no_devname store Dev email waqasamjad1232@gmail.com; developer_name empty; no business domain verifiable.
- broad_host_scripting manifest scripting + host_permissions *://*/* enables JS injection on all sites; unjustified for cursor extension.
- dom_sink_innerhtml crx innerHTML sink in main.4964ab1e.js with no CSP; DOM-XSS risk elevated.
- install_perm_anomaly api 806 installs, HIGH-tier permissions — small_install_high_perm and tail_attack_surface both true.
- stale_15mo store Last updated May 2025, 15 months since update; maintenance risk elevated (6-12mo band).
Permissions Breakdown
- storage low Standard local data persistence; low risk on its own.
- unlimitedStorage low Allows larger local storage quota; minimal risk for a cursor extension.
- scripting high Combined with *://*/* host access allows arbitrary JS injection on all sites.
- *://*/* high Broad host access; cursor extension has no justified need for all URLs.
Pillar Scores
Permissions7.00
Reputation7.00
Network4.50
Webstore8.00
Maintenance6.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 10:42
Listing SHA
acfc3f77a96f…
Force block
— not fired
Score recovered
no
Elapsed
—