Minecraft Cursor for Chrome
kkchefmfekacdingcjkgiaggdafolhen
Risk Score
4.74
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Brand impersonation: uses 'Minecraft' (Mojang) brand without confirmed ownership — confirmed by brand_mention.
- Uninstall + install URL hijack to tabplugins.com marketing pages — monetization shell indicators.
- Broad host access (*://*/*) + scripting on all sites with innerHTML DOM-XSS sink and no CSP.
- Privacy policy admits data collection and third-party sharing with no retention disclosure.
- No developer name listed; missing Offered-by transparency despite verified_publisher claim.
Evidence
- brand_impersonation api brand_mention.is_impersonation=true for 'minecraft'; confirmed_owner=false; developer is tabplugins.com.
- uninstall_url_hijack crx chrome.runtime.setUninstallURL targets tabplugins.com/cursors/ with UTM tracking params.
- install_url_hijack crx onInstalled opens tabplugins.com/minecraft-cursor/ with UTM params — traffic monetization pattern.
- broad_host_access_plus_scripting manifest host_permissions *://*/* + scripting permission + content_scripts on *://*/* — runs on every site.
- dom_xss_sink_no_csp crx innerHTML user-controlled sink in main.4964ab1e.js with csp_present=false; DOM-XSS risk elevated.
- privacy_policy_data_collection_third_party api Policy fetched: scope_extension=true, data_collection=true, third_party_sharing=true, retention=false.
- no_developer_name store developer_name is empty string; reduced accountability signal despite verified_publisher=true.
- verified_publisher store verified_publisher=true; provides partial accountability discount but does not offset monetization flags.
Permissions Breakdown
- storage low Standard local persistence for cursor settings.
- unlimitedStorage low Expands storage quota; low standalone risk.
- scripting high Allows programmatic script injection into any page via host_permissions *://*/*.
- *://*/* (host_permissions) high Broad host access covering every site; amplifies scripting and content_script risk.
- *://*/* (content_scripts_matches) high Content script runs on every page, expanding attack surface for XSS/data access.
Pillar Scores
Permissions6.00
Reputation5.50
Network2.00
Webstore8.50
Maintenance0.00
Privacy2.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 15:12
Listing SHA
8678d66630a9…
Force block
— not fired
Score recovered
no
Elapsed
—