Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Spiderman Cursor - Custom Cursor for Chrome

mopjnoodlnbnkocfefcgnmnlbcmgekof
Risk Score
4.29
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Entertainment
Installs 2,000
Rating 5.0
Last updated 2026-06-18 (2 months ago)
Manifest version MV3
CSP present ❌ no
Developer info@tabplugins.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Uninstall and install URL hijacks redirect users to developer marketing pages, monetization behavior.
  • scripting + *://*/* host permissions allow arbitrary JS injection into every visited site.
  • Privacy policy admits data collection and third-party sharing without retention disclosure.
  • No CSP declared (MV3); innerHTML DOM-XSS sink present in bundled React JS.
  • Install/uninstall hijack pattern typical of low-quality cursor/theme extension clusters.

Evidence

  • uninstall_url_hijack crx setUninstallURL targets tabplugins.com/cursors/ via Google redirect wrapper — monetization funnel.
  • install_url_hijack crx onInstalled opens tabplugins.com/spiderman-cursor/ with UTM tracking params.
  • broad_host_access manifest host_permissions and content_scripts both match *://*/* — full site reach for a cursor extension.
  • dom_sink_innerhtml_userctrl crx innerHTML write from variable in main.4964ab1e.js; no CSP to mitigate DOM-XSS.
  • privacy_third_party_sharing store Policy confirms data collection + third-party sharing; no retention period disclosed.
  • no_csp manifest content_security_policy is null; MV3 default applies but no explicit hardening.
  • install_count_low_high_perm store Only 2,000 installs yet scripting+*://*/* claimed; cursor function does not require broad host access.
  • category_mismatch_broad_access manifest Entertainment/cursor extension requesting scripting on all URLs is scope-mismatched.

Permissions Breakdown

  • storage low Standard key-value persistence; low intrinsic risk.
  • unlimitedStorage low Allows larger local data; low risk alone.
  • scripting high Programmatic script injection into pages; HIGH when paired with *://*/* host access.
  • *://*/* (host_permissions) high Broad host access covering all URLs; amplifies scripting and data-read capabilities.

Pillar Scores

Permissions5.50
Reputation5.50
Network2.00
Webstore7.00
Maintenance0.00
Privacy2.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 16:36
Listing SHA 6cad3e798aa5…
Force block — not fired
Score recovered no
Elapsed