Demon Slayer Cursor - Custom Anime Cursor for Chrome
lmnmfkhppclolpdbdabpbhladegibpgi
Risk Score
6.97
Risk Level:
High
Recommendation:
🚫 BLOCK
Top Risks
- Uninstall URL hijack to tabplugins.com and install URL hijack — classic low-quality monetization shell pattern.
- Free-webmail dev (gmail), no developer name, no verified publisher — unaccountable operator.
- Privacy policy is Google's own policy, not scoped to this extension — admits data collection & 3rd-party sharing.
- scripting + *://*/* gives full page JS injection on every site; cursor extension has no legitimate need for this breadth.
- small_install_high_perm anomaly: only 421 installs with HIGH-tier permissions — tail attack surface.
Evidence
- uninstall_url_hijack manifest chrome.runtime.setUninstallURL → https://tabplugins.com/cursors/ (3rd-party monetization domain).
- install_url_hijack manifest onInstalled opens https://tabplugins.com/demon-slayer-cursor-custom-anime-cursor-for-chrome/.
- free_webmail_dev_no_name store Developer email waqasamjad1232@gmail.com; developer_name is empty; no verified publisher.
- privacy_policy_generic_google store Privacy URL is Google account policy (scope_extension=false, data_collection=true, third_party_sharing=true).
- broad_host_scripting manifest scripting + *://*/* host_permissions + content_scripts on all URLs — full JS injection capability.
- dom_sink_innerhtml crx innerHTML assignment from variable in main.4964ab1e.js — DOM-XSS sink with no CSP.
- install_perm_anomaly api 421 installs, HIGH-tier permissions: small_install_high_perm=true, tail_attack_surface=true.
- maintenance_stale store 15 months since last update; 6-12mo band (+3.5) but 12-24 boundary places it at +6.0.
Permissions Breakdown
- storage low Standard local data persistence; low standalone risk.
- unlimitedStorage low Allows unlimited local storage; minor risk amplifier.
- scripting high Allows JS injection into pages; critical with *://*/* host access.
- *://*/* high Broad host access across all sites; enables scripting on every page visited.
Pillar Scores
Permissions7.50
Reputation8.50
Network2.00
Webstore8.00
Maintenance6.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 15:20
Listing SHA
16da30361bc1…
Force block
— not fired
Score recovered
no
Elapsed
—