Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Baseball Cursor - Custom Sports Cursor for Chrome

ngiaafjblpmiejfgcnfcolhdccmaafjg
Risk Score
3.68
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category Other
Installs 213
Rating 5.0
Last updated 2026-06-21 (2 months ago)
Manifest version MV3
CSP present ❌ no
Developer info@tabplugins.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Uninstall URL hijack routes through Google redirect to tabplugins.com — classic traffic monetization pattern.
  • Install URL hijack opens third-party page on install with UTM campaign tracking.
  • scripting + *://*/* grants JS injection on every site despite trivial stated function.
  • Privacy policy admits third-party data sharing without data retention disclosure.
  • innerHTML DOM-XSS sink in main bundle; no CSP to mitigate.

Evidence

  • uninstall_url_hijack manifest setUninstallURL targets google.com redirect → tabplugins.com/cursors/ — monetization fingerprint.
  • install_url_hijack manifest onInstalled opens tabplugins.com with utm_campaign=cursors — install traffic capture.
  • host_permissions_broad manifest host_permissions *://*/* combined with scripting on a cursor extension — scope mismatch.
  • small_install_high_perm store 213 installs but HIGH-tier host+scripting permissions — tail attack surface.
  • privacy_third_party_sharing api Policy fetched; scope_extension=true but third_party_sharing=true, retention=false.
  • dom_sink_innerhtml crx innerHTML assignment in main.4964ab1e.js; no CSP present to mitigate DOM-XSS.
  • verified_publisher store tabplugins.com verified publisher; resolves=true, not throwaway — partial trust credit.
  • no_developer_name store developer_name field empty in listing — minor accountability gap.

Permissions Breakdown

  • storage low Stores cursor preferences locally; low risk.
  • unlimitedStorage low Extends storage quota; minor risk uplift only.
  • scripting medium Allows JS injection into pages; medium risk on its own.
  • *://*/* high Broad host access — scripting+host permits read/write on every site.

Pillar Scores

Permissions5.50
Reputation4.00
Network2.00
Webstore6.00
Maintenance0.00
Privacy2.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 16:41
Listing SHA 223d946c6fd4…
Force block — not fired
Score recovered no
Elapsed