Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Demon Slayer Cursor - Custom Anime Cursor for Chrome

lmnmfkhppclolpdbdabpbhladegibpgi
Risk Score
6.97
Risk Level: High
Recommendation: 🚫 BLOCK
Category Entertainment
Installs 421
Rating
Last updated 2025-05-28 (15 months ago)
Manifest version MV3
CSP present ❌ no
Developer waqasamjad1232@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Uninstall URL hijack to tabplugins.com and install URL hijack — classic low-quality monetization shell pattern.
  • Free-webmail dev (gmail), no developer name, no verified publisher — unaccountable operator.
  • Privacy policy is Google's own policy, not scoped to this extension — admits data collection & 3rd-party sharing.
  • scripting + *://*/* gives full page JS injection on every site; cursor extension has no legitimate need for this breadth.
  • small_install_high_perm anomaly: only 421 installs with HIGH-tier permissions — tail attack surface.

Evidence

  • uninstall_url_hijack manifest chrome.runtime.setUninstallURL → https://tabplugins.com/cursors/ (3rd-party monetization domain).
  • install_url_hijack manifest onInstalled opens https://tabplugins.com/demon-slayer-cursor-custom-anime-cursor-for-chrome/.
  • free_webmail_dev_no_name store Developer email waqasamjad1232@gmail.com; developer_name is empty; no verified publisher.
  • privacy_policy_generic_google store Privacy URL is Google account policy (scope_extension=false, data_collection=true, third_party_sharing=true).
  • broad_host_scripting manifest scripting + *://*/* host_permissions + content_scripts on all URLs — full JS injection capability.
  • dom_sink_innerhtml crx innerHTML assignment from variable in main.4964ab1e.js — DOM-XSS sink with no CSP.
  • install_perm_anomaly api 421 installs, HIGH-tier permissions: small_install_high_perm=true, tail_attack_surface=true.
  • maintenance_stale store 15 months since last update; 6-12mo band (+3.5) but 12-24 boundary places it at +6.0.

Permissions Breakdown

  • storage low Standard local data persistence; low standalone risk.
  • unlimitedStorage low Allows unlimited local storage; minor risk amplifier.
  • scripting high Allows JS injection into pages; critical with *://*/* host access.
  • *://*/* high Broad host access across all sites; enables scripting on every page visited.

Pillar Scores

Permissions7.50
Reputation8.50
Network2.00
Webstore8.00
Maintenance6.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 15:20
Listing SHA 16da30361bc1…
Force block — not fired
Score recovered no
Elapsed