Blue Lock Cursor ★ Custom Cursor for Chrome™
nlppklcmgfgaploglaakimdlfgeinajj
Risk Score
5.05
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Uninstall URL hijack sends users to yowgames.com with UTM tracking on removal.
- Install URL hijack sends users to yowgames.com with UTM tracking on install.
- Privacy policy does not scope to this extension and admits data collection + third-party sharing (D rule: +10 privacy).
- Content script injected on all URLs (*://*/*) for a cursor extension — broad reach with no host permission justification.
- Free-webmail developer (gmail) with no verified publisher, policy on unrelated game portal domain.
Evidence
- uninstall_url_hijack manifest chrome.runtime.setUninstallURL targets yowgames.com with UTM tracking params.
- install_url_hijack manifest onInstalled opens yowgames.com with UTM install tracking params.
- content_scripts_broad manifest content_scripts_matches=[*://*/*] injects into every page for a cursor-cosmetic extension.
- privacy_policy_generic_admits_sharing store Policy on yowgames.com: scope_extension=false, data_collection=true, third_party_sharing=true => +10 privacy.
- free_webmail_dev store Developer email uralsinem026@gmail.com; no verified publisher badge; no business domain.
- js_external_hosts crx Extension contacts chrome.google.com and yowgames.com externally.
- maintenance store months_since_update=9 (3-12mo band) -> +3.5 maintenance pillar.
- cve_findings_raw_empty crx No CVEs found; jquery 3.6.0 bundled but no OSV hits reported.
Permissions Breakdown
- storage low Stores cursor preference locally; low risk on its own.
- content_scripts *://*/* high Injects JS into every page visited; broad reach despite narrow declared permissions.
Pillar Scores
Permissions2.30
Reputation6.50
Network2.00
Webstore8.00
Maintenance3.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 16:44
Listing SHA
7f2332f56777…
Force block
— not fired
Score recovered
no
Elapsed
—