Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Hunter x Hunter Cursor - Custom Anime Cursor for Chrome

ijccagageaijbfaefkflkepnglppdlnn
Risk Score
4.09
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Entertainment
Installs 585
Rating 5.0
Last updated 2026-06-18 (2 months ago)
Manifest version MV3
CSP present ❌ no
Developer info@tabplugins.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Uninstall & install URL hijack redirect users to developer marketing pages — classic monetization shell.
  • scripting + *://*/*eable JS injection on every site with no CSP guard.
  • Privacy policy admits data collection and third-party sharing with no retention period disclosed.
  • Small install count (585) combined with HIGH-tier permissions is a tail-attack-surface signal.
  • No developer name listed; verified publisher badge doesn't offset anonymous identity.

Evidence

  • uninstall_url_hijack crx setUninstallURL points to tabplugins.com marketing page with UTM params — monetization redirect.
  • install_url_hijack crx onInstalled opens tabplugins.com/hunter-x-hunter-cursor/ with UTM params.
  • broad_host_scripting manifest scripting + host_permissions *://*/* allows JS injection on all sites; no CSP present.
  • dom_sink_innerhtml_userctrl crx innerHTML assignment from variable in main.4964ab1e.js — DOM-XSS sink; no CSP mitigates.
  • small_install_high_perm store 585 installs with HIGH-tier permissions (scripting + all_urls) — install_perm_anomaly flagged.
  • privacy_policy_third_party_sharing api Policy scoped to extension, collects data, shares with third parties, no retention period stated.
  • no_developer_name store developer_name is empty string; no 'Offered by' identity beyond email domain.
  • verified_publisher store Verified publisher badge present — partial reputation credit applied.

Permissions Breakdown

  • storage low Stores cursor preferences locally; low standalone risk.
  • unlimitedStorage low Allows unlimited local storage; modest risk for a cursor extension.
  • scripting high Allows arbitrary JS injection into all pages via host_permissions *://*/*.
  • *://*/* (host_permissions) high Broad host access pairs with scripting — can read/modify every page visited.

Pillar Scores

Permissions5.50
Reputation4.50
Network2.00
Webstore7.50
Maintenance0.00
Privacy2.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 10:50
Listing SHA 9fcd04bdea95…
Force block — not fired
Score recovered no
Elapsed