Anime Cursor - Custom Cursor for Chrome™ - All in One Anime Cursors
kbgpgmcbehkiiooamcldaccehdcdenmn
Risk Score
2.91
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- Broad host_permissions (*://*/*) + scripting allows content injection on every visited site.
- Uninstall and install URL hijack redirect users to developer's marketing page.
- innerHTML DOM-XSS sink in bundled JS (no CSP to mitigate) — exploitation surface if cursor data is attacker-controlled.
- Developer name missing from listing despite verified publisher badge — accountability gap.
- No CSP defined (csp_present=false); MV3 strict-default applies but innerHTML findings increase residual XSS risk.
Evidence
- broad_host_permissions manifest host_permissions and content_scripts_matches both set to *://*/* — runs on every page.
- uninstall_url_hijack crx setUninstallURL targets gameograf.com marketing page with UTM params.
- install_url_hijack crx onInstalled opens gameograf.com marketing page with UTM params.
- dom_sink_innerhtml crx Two JS files contain unguarded innerHTML assignments; no CSP to limit exploitation.
- verified_publisher_featured store Extension carries both verified_publisher and is_featured_by_google badges — reputation discounts applied.
- privacy_policy_adequate api Policy fetched; scope_extension=true, data_collection=true, retention=true, third_party_sharing=true.
- no_developer_name store developer_name field is empty despite verified publisher status.
- js_external_hosts crx Contacts api.gameograf.com, gameograf.com, chrome.google.com, reactjs.org — 4 distinct domains.
Permissions Breakdown
- storage low Stores user cursor preferences locally; low risk.
- scripting medium Allows programmatic script injection into pages; elevated risk with broad host access.
- *://*/*HostPermission high Broad host access to all URLs; enables content injection on every site visited.
Pillar Scores
Permissions4.50
Reputation2.00
Network2.00
Webstore5.00
Maintenance0.00
Privacy0.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-02 10:36
Listing SHA
b95f0c577bc0…
Force block
— not fired
Score recovered
no
Elapsed
—