BTS Cursor ★ Custom Cursor for Chrome™
jddaakabhmcbgfnbkgcjfeigbnbcdjgn
Risk Score
5.49
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Uninstall URL hijack sends user to yowgames.com with UTM tracking on removal.
- Install URL hijack fires yowgames.com UTM ping on install — undisclosed data collection.
- Privacy policy (yowgames.com) admits data collection and third-party sharing but is not scoped to this extension.
- Free-webmail developer (gmail) with no verified business identity; extension ties to separate yowgames.com domain.
- Content script injected on *://*/* gives full DOM read/write access on every site visited.
Evidence
- uninstall_url_hijack crx chrome.runtime.setUninstallURL targets yowgames.com with UTM params; 3rd-party tracking on uninstall.
- install_url_hijack crx onInstalled opens yowgames.com with UTM params; undisclosed install-time redirect.
- privacy_policy_scope_mismatch api Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true — generic, not scoped to extension.
- free_webmail_developer store Developer email ayseozkacar237@gmail.com; no verified business; dev name 'live4kwallpaper' unverified.
- content_script_broad manifest content_scripts_matches: *://*/* — JS injected on every page.
- js_external_hosts crx External JS hosts: chrome.google.com, yowgames.com.
- rating_low store Rating 3.4 — below acceptable threshold; small user base (2000 installs).
- no_cve_findings crx jquery 3.6.0 bundled; cve_findings_raw empty — no known CVEs triggered.
Permissions Breakdown
- storage low Stores cursor preferences locally; low standalone risk.
- content_scripts *://*/* high Injects JS into every page the user visits; high reach capability.
Pillar Scores
Permissions3.50
Reputation7.50
Network2.00
Webstore8.00
Maintenance3.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-27 03:56
Listing SHA
e52acc6e2c8f…
Force block
— not fired
Score recovered
no
Elapsed
—