Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Custom Cursor for Chrome™

ogdlpmhglpejoiomcodnpjnfgcpmgale
Risk Score
4.84
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Other
Installs 5,000,000
Rating 4.7
Last updated 2026-08-18
Manifest version MV3
CSP present ❌ no
Developer blife450@gmail.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Gmail developer account (blife450@gmail.com) with no verified business identity raises accountability concerns.
  • Content scripts injected into <all_urls> — every page visited is in scope for the extension.
  • Privacy policy fetch failed; data handling completely unverifiable despite 5M installs.
  • install_url and uninstall_url redirect to custom-cursor.com with UTM tracking parameters.
  • innerHTML DOM sink + new Function() constructor present; no CSP to mitigate XSS risk on all pages.

Evidence

  • host_permission_all_urls manifest <all_urls> host permission + content_scripts on <all_urls>; scripting on all pages.
  • gmail_developer store Developer email blife450@gmail.com — free webmail, no verified business entity.
  • privacy_policy_fetch_failed api privacy_policy_classification.fetched==false (HTTPError); policy content unverifiable.
  • install_url_hijack crx onInstalled opens https://custom-cursor.com/successful-installation with UTM params.
  • uninstall_url_hijack crx setUninstallURL points to https://custom-cursor.com/uninstall with UTM params.
  • code_findings_function_constructor_innerHTML crx new Function() in popup.min.js & content.js; innerHTML DOM sink in popup.min.js; no CSP.
  • verified_publisher_featured store Extension is verified publisher AND featured by Google; partially offsets reputation concerns.
  • js_external_hosts crx External JS hosts: custom-cursor.com, fb.me, github.com, reactjs.org (3 countries).

Permissions Breakdown

  • scripting medium Can inject JS into pages; paired with <all_urls> host permission this is high-reach.
  • storage low Stores extension settings locally.
  • unlimitedStorage low Allows unbounded local storage; minor abuse potential.
  • notifications low Can show desktop notifications; low direct risk.
  • alarms low Schedules background tasks; low risk alone.
  • <all_urls> (host_permission) high Content scripts injected into every page the user visits; broad attack surface.

Pillar Scores

Permissions5.50
Reputation6.00
Network2.00
Webstore5.50
Maintenance0.00
Privacy10.00
Code Quality4.00
CVE Exposure0.00

Scoring History

<fsssiedxa xx psssiedx 5.26 Medium review 2026-08-18
<fsssiedxa$'sssiedx 4.74 Medium review 2026-08-18
<fsssiedxa$"sssiedx 5.25 Medium review 2026-08-18
xx pfsssiedxasssiedx 4.97 Medium review 2026-08-18
"fsssiedxa xx psssiedx 4.55 Medium review 2026-08-18
"fsssiedxa$'sssiedx 5.01 Medium review 2026-08-18
'fsssiedxafdsaxax><!--></ScRiPt>asddsssiedx 4.94 Medium review 2026-08-18
%27fsssiedxa sssiedx 4.83 Medium review 2026-08-18
&#x22;fsssiedxa&#x27;sssiedx 4.85 Medium review 2026-08-18
&#x22;fsssiedxa$'sssiedx 4.97 Medium review 2026-08-18
fsssiedxa<sssiedx 5.49 Medium review 2026-08-18
fsssiedxasssiedx 4.53 Medium review 2026-08-08
sssieddrubricxsx 4.53 Medium review 2026-08-08
%76%33%2E%36%39%32%35%38%22%28%29%3B%7D%5D%39%34%38%35 5.58 Medium review 2026-08-05
"dfbzzzzzzzzbbbccccdddeeexca".replace("z","o") 5.53 Medium review 2026-08-05
<th:t="${dfb}#foreach 4.58 Medium review 2026-08-05
v3.6 4.84 Medium review 2026-06-16

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 08:01
Listing SHA e9cfd398dca3…
Force block — not fired
Score recovered no
Elapsed 25.8s