Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

One-Punch Man Cursor - Custom Anime Cursor for Chrome

lalcmboamkljbdlgjfockddndpfoiojc
Risk Score
4.61
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Entertainment
Installs 176
Rating
Last updated 2026-06-28 (2 months ago)
Manifest version MV3
CSP present ❌ no
Developer info@tabplugins.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Uninstall & install URL hijacks redirect to tabplugins.com marketing pages — classic monetization shell pattern.
  • scripting + *://*/* gives full script injection on every site; very broad for a cursor extension.
  • No CSP + innerHTML DOM-XSS sink — unsafe DOM manipulation with no mitigation layer.
  • Privacy policy admits data collection and third-party sharing without retention disclosure.
  • Low install count (176) with HIGH-tier permissions flags tail-attack-surface anomaly.

Evidence

  • uninstall_url_hijack crx setUninstallURL → tabplugins.com/cursors/ with UTM params; monetization redirect confirmed.
  • install_url_hijack crx onInstalled opens tabplugins.com promo page with UTM; affiliate/monetization pattern.
  • broad_host_permissions manifest host_permissions *://*/* + content_scripts *://*/* + scripting = full-site control.
  • dom_sink_innerhtml_userctrl crx innerHTML sink in main.4964ab1e.js; no CSP present → elevated XSS risk.
  • privacy_policy_third_party_sharing store Policy admits data collection + third-party sharing; retention not disclosed.
  • install_perm_anomaly api 176 installs + HIGH-tier permissions (scripting + all_urls) = small-install high-perm anomaly.
  • no_csp crx content_security_policy is null; MV3 default applies but no explicit hardening.
  • unverified_developer store No verified publisher badge, no featured badge; WallExt / tabplugins.com unverified.

Permissions Breakdown

  • storage low Stores cursor preferences locally; low risk alone.
  • unlimitedStorage low Extends storage quota; low risk for cursor asset caching.
  • scripting high Allows programmatic script injection into any page; significant capability.
  • *://*/* high Broad host access across all sites; pairs with scripting for full page control.
  • content_scripts *://*/* high Content scripts run on every page visited; full DOM access on all sites.

Pillar Scores

Permissions6.50
Reputation5.50
Network2.00
Webstore7.50
Maintenance0.00
Privacy2.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 15:14
Listing SHA ec2fc01a2db4…
Force block — not fired
Score recovered no
Elapsed