Custom Cursor for Chrome™
ogdlpmhglpejoiomcodnpjnfgcpmgale
Risk Score
4.84
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Gmail developer account (blife450@gmail.com) with no verified business identity raises accountability concerns.
- Content scripts injected into <all_urls> — every page visited is in scope for the extension.
- Privacy policy fetch failed; data handling completely unverifiable despite 5M installs.
- install_url and uninstall_url redirect to custom-cursor.com with UTM tracking parameters.
- innerHTML DOM sink + new Function() constructor present; no CSP to mitigate XSS risk on all pages.
Evidence
- host_permission_all_urls manifest <all_urls> host permission + content_scripts on <all_urls>; scripting on all pages.
- gmail_developer store Developer email blife450@gmail.com — free webmail, no verified business entity.
- privacy_policy_fetch_failed api privacy_policy_classification.fetched==false (HTTPError); policy content unverifiable.
- install_url_hijack crx onInstalled opens https://custom-cursor.com/successful-installation with UTM params.
- uninstall_url_hijack crx setUninstallURL points to https://custom-cursor.com/uninstall with UTM params.
- code_findings_function_constructor_innerHTML crx new Function() in popup.min.js & content.js; innerHTML DOM sink in popup.min.js; no CSP.
- verified_publisher_featured store Extension is verified publisher AND featured by Google; partially offsets reputation concerns.
- js_external_hosts crx External JS hosts: custom-cursor.com, fb.me, github.com, reactjs.org (3 countries).
Permissions Breakdown
- scripting medium Can inject JS into pages; paired with <all_urls> host permission this is high-reach.
- storage low Stores extension settings locally.
- unlimitedStorage low Allows unbounded local storage; minor abuse potential.
- notifications low Can show desktop notifications; low direct risk.
- alarms low Schedules background tasks; low risk alone.
- <all_urls> (host_permission) high Content scripts injected into every page the user visits; broad attack surface.
Pillar Scores
Permissions5.50
Reputation6.00
Network2.00
Webstore5.50
Maintenance0.00
Privacy10.00
Code Quality4.00
CVE Exposure0.00
Scoring History
| <fsssiedxa xx psssiedx | 5.26 | Medium | review | 2026-08-18 |
| <fsssiedxa$'sssiedx | 4.74 | Medium | review | 2026-08-18 |
| <fsssiedxa$"sssiedx | 5.25 | Medium | review | 2026-08-18 |
| xx pfsssiedxasssiedx | 4.97 | Medium | review | 2026-08-18 |
| "fsssiedxa xx psssiedx | 4.55 | Medium | review | 2026-08-18 |
| "fsssiedxa$'sssiedx | 5.01 | Medium | review | 2026-08-18 |
| 'fsssiedxafdsaxax><!--></ScRiPt>asddsssiedx | 4.94 | Medium | review | 2026-08-18 |
| %27fsssiedxa sssiedx | 4.83 | Medium | review | 2026-08-18 |
| "fsssiedxa'sssiedx | 4.85 | Medium | review | 2026-08-18 |
| "fsssiedxa$'sssiedx | 4.97 | Medium | review | 2026-08-18 |
| fsssiedxa<sssiedx | 5.49 | Medium | review | 2026-08-18 |
| fsssiedxasssiedx | 4.53 | Medium | review | 2026-08-08 |
| sssieddrubricxsx | 4.53 | Medium | review | 2026-08-08 |
| %76%33%2E%36%39%32%35%38%22%28%29%3B%7D%5D%39%34%38%35 | 5.58 | Medium | review | 2026-08-05 |
| "dfbzzzzzzzzbbbccccdddeeexca".replace("z","o") | 5.53 | Medium | review | 2026-08-05 |
| <th:t="${dfb}#foreach | 4.58 | Medium | review | 2026-08-05 |
| v3.6 | 4.84 | Medium | review | 2026-06-16 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 08:01
Listing SHA
e9cfd398dca3…
Force block
— not fired
Score recovered
no
Elapsed
25.8s