Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Minecraft Cursor for Chrome

kkchefmfekacdingcjkgiaggdafolhen
Risk Score
4.74
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Entertainment
Installs 2,000
Rating 5.0
Last updated 2026-06-18 (2 months ago)
Manifest version MV3
CSP present ❌ no
Developer info@tabplugins.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Brand impersonation: uses 'Minecraft' (Mojang) brand without confirmed ownership — confirmed by brand_mention.
  • Uninstall + install URL hijack to tabplugins.com marketing pages — monetization shell indicators.
  • Broad host access (*://*/*) + scripting on all sites with innerHTML DOM-XSS sink and no CSP.
  • Privacy policy admits data collection and third-party sharing with no retention disclosure.
  • No developer name listed; missing Offered-by transparency despite verified_publisher claim.

Evidence

  • brand_impersonation api brand_mention.is_impersonation=true for 'minecraft'; confirmed_owner=false; developer is tabplugins.com.
  • uninstall_url_hijack crx chrome.runtime.setUninstallURL targets tabplugins.com/cursors/ with UTM tracking params.
  • install_url_hijack crx onInstalled opens tabplugins.com/minecraft-cursor/ with UTM params — traffic monetization pattern.
  • broad_host_access_plus_scripting manifest host_permissions *://*/* + scripting permission + content_scripts on *://*/* — runs on every site.
  • dom_xss_sink_no_csp crx innerHTML user-controlled sink in main.4964ab1e.js with csp_present=false; DOM-XSS risk elevated.
  • privacy_policy_data_collection_third_party api Policy fetched: scope_extension=true, data_collection=true, third_party_sharing=true, retention=false.
  • no_developer_name store developer_name is empty string; reduced accountability signal despite verified_publisher=true.
  • verified_publisher store verified_publisher=true; provides partial accountability discount but does not offset monetization flags.

Permissions Breakdown

  • storage low Standard local persistence for cursor settings.
  • unlimitedStorage low Expands storage quota; low standalone risk.
  • scripting high Allows programmatic script injection into any page via host_permissions *://*/*.
  • *://*/* (host_permissions) high Broad host access covering every site; amplifies scripting and content_script risk.
  • *://*/* (content_scripts_matches) high Content script runs on every page, expanding attack surface for XSS/data access.

Pillar Scores

Permissions6.00
Reputation5.50
Network2.00
Webstore8.50
Maintenance0.00
Privacy2.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 15:12
Listing SHA 8678d66630a9…
Force block — not fired
Score recovered no
Elapsed