Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

My Hero Academia Cursor - Custom Anime Cursor for Chrome

oalffknmmdipjphppkcnffnfefljelcm
Risk Score
3.22
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category Entertainment
Installs 689
Rating 5.0
Last updated 2026-06-18 (2 months ago)
Manifest version MV3
CSP present ❌ no
Developer info@tabplugins.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • scripting + *://*/*ː broad script injection into every page the user visits, far beyond cursor-swap need.
  • Uninstall and install URL hijack to tabplugins.com — monetization redirect pattern on both lifecycle events.
  • Privacy policy discloses third-party data sharing with no retention period; scope nominally matches extension.
  • No developer name listed; low install count (689) with high-tier permissions flags tail-attack-surface anomaly.
  • DOM-XSS sink (innerHTML) in bundled JS with no CSP; elevates exploitability if remote content ever flows in.

Evidence

  • host_permissions + scripting manifest scripting + *://*/* grants injection into every visited page; excessive for a cursor-swap extension.
  • uninstall_url_hijack + install_url_hijack crx Both onInstalled and uninstall events redirect to tabplugins.com marketing URLs — monetization shell pattern.
  • privacy_policy third_party_sharing true, retention false api Policy admits third-party sharing but specifies no retention period; inadequate for broad-host extension.
  • install_perm_anomaly small_install_high_perm api 689 installs with HIGH-tier permission (scripting + all_urls) — tail attack surface flag.
  • dom_sink_innerhtml_userctrl crx innerHTML sink in main bundle; no CSP present on MV3 extension raises DOM-XSS exploitability.
  • no developer_name store Developer name field is empty; reduces accountability signal despite verified_publisher badge.
  • verified_publisher store Publisher verified by Google — partial trust anchor, but does not explain broad permissions.
  • csp_present false + MV3 manifest No explicit CSP declared; MV3 default applies but innerHTML sink still present in bundle.

Permissions Breakdown

  • storage low Used to persist cursor preferences locally.
  • unlimitedStorage low Extends storage quota; low standalone risk for cursor assets.
  • scripting high Allows programmatic script injection into all pages via host_permissions *://*/*.
  • *://*/* (host_permissions) high Full cross-origin host access; pairs with scripting for broad page manipulation.

Pillar Scores

Permissions6.50
Reputation4.00
Network2.00
Webstore6.50
Maintenance0.00
Privacy2.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 16:48
Listing SHA 41c6f95ad2b6…
Force block — not fired
Score recovered no
Elapsed