Hello Kitty Cursor - Custom Kawaii Cursor for Chrome
lmjdeimbphcbnfekpgblhlbhknpmaoij
Risk Score
4.34
Risk Level:
Medium
Recommendation:
🚫 BLOCK
Top Risks
- Uninstall URL hijack redirects to tabplugins.com — classic monetization shell behavior.
- Install URL hijack opens tabplugins.com on install — unsolicited third-party redirect.
- Privacy policy is Google's own policy, not scoped to this extension; admits data collection and third-party sharing.
- scripting + *://*/*ives full read/write access to every page the user visits.
- Gmail developer with no verified publisher status or business domain; free-webmail accountability gap.
Evidence
- uninstall_url_hijack crx chrome.runtime.setUninstallURL → https://tabplugins.com/cursors/ (third-party monetization domain).
- install_url_hijack crx onInstalled opens https://tabplugins.com/hello-kitty-cursor-custom-kawaii-cursor-for-chrome/.
- privacy_policy_generic store Policy URL is Google Account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
- broad_host_access manifest host_permissions and content_scripts_matches both set to *://*/* with scripting permission.
- free_webmail_dev store developer_email=heroking15@gmail.com; no verified publisher; no business domain.
- dom_sink_innerhtml crx innerHTML user-controlled sink in main.4964ab1e.js; no CSP present (MV3 default only).
- js_external_hosts crx Extension references chrome.google.com, reactjs.org, tabplugins.com as external JS hosts.
- no_csp_declared manifest content_security_policy is null; csp_present=false; DOM sink risk elevated.
Permissions Breakdown
- storage low Stores cursor preferences locally; low standalone risk.
- unlimitedStorage low Extended storage quota; minimal risk for cursor assets.
- scripting high Allows programmatic script injection into all pages via host_permissions *://*/*.
- *://*/* (host_permissions) high Broad host access paired with scripting — can read/modify every page.
Pillar Scores
Permissions5.50
Reputation6.50
Network4.00
Webstore7.50
Maintenance1.50
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 15:18
Listing SHA
254268ae53ed…
Force block
— not fired
Score recovered
no
Elapsed
—