Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Soccer Cursor - Custom Sports Cursor for Chrome

lmjocpjbilfamkogfpbecdhefcjffbhb
Risk Score
4.53
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Other
Installs 318
Rating
Last updated 2026-06-28 (2 months ago)
Manifest version MV3
CSP present ❌ no
Developer info@tabplugins.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Uninstall URL hijack redirects to tabplugins.com/cursors/ — classic monetization/tracking shell pattern.
  • Install URL hijack opens tabplugins.com marketing page on extension install.
  • scripting + *://*/* host access gives full programmatic control over every visited page.
  • Privacy policy admits third-party data sharing without retention disclosure.
  • Small install base (318) with HIGH-tier permissions — elevated tail-attack-surface concern.

Evidence

  • uninstall_url_hijack crx chrome.runtime.setUninstallURL targets https://tabplugins.com/cursors/ — monetization shell indicator (+3.0 webstore).
  • install_url_hijack crx onInstalled opens tabplugins.com marketing page with UTM tracking — install hijack (+2.0 webstore).
  • broad_host_permissions manifest host_permissions *://*/* + scripting: full page access on all sites.
  • dom_sink_innerhtml_userctrl crx innerHTML sink in main.4964ab1e.js; no CSP in MV3 manifest to mitigate.
  • privacy_policy_third_party_sharing store Policy fetched: scope_extension=true, data_collection=true, third_party_sharing=true, retention=false.
  • install_perm_anomaly api 318 installs with HIGH-tier permission (scripting + all_urls) — small_install_high_perm flagged.
  • no_verified_publisher store Developer WallExt not verified; no featured badge; unrecognized org.
  • csp_absent manifest csp_present=false; no content_security_policy declared in MV3 extension.

Permissions Breakdown

  • storage low Stores cursor preferences locally; low risk.
  • unlimitedStorage low Extended local storage; minor risk elevation.
  • scripting high Programmatic script injection into any page via broad host_permissions.
  • *://*/* (host_permissions) high Grants access to every site the user visits; broad reach.

Pillar Scores

Permissions5.50
Reputation6.00
Network2.00
Webstore7.50
Maintenance0.00
Privacy2.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 15:18
Listing SHA 6fc78b2b7ebe…
Force block — not fired
Score recovered no
Elapsed