Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Hunter x Hunter Cursor ★ Custom Cursor for Chrome™

oodhphlpepgoccemjgpedagbpfelcpdl
Risk Score
5.58
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Entertainment
Installs 188
Rating 5.0
Last updated 2025-11-30 (9 months ago)
Manifest version MV3
CSP present ❌ no
Developer ayseozkacar237@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Uninstall URL hijack: redirects to yowgames.com affiliate/UTM URL on removal — monetization shell pattern.
  • Install URL hijack: opens yowgames.com UTM URL on install — unsolicited navigation on first run.
  • Privacy policy fetch failed (SSLError); third_party_silence=true; no verifiable data-handling disclosure.
  • Free-webmail developer (gmail) with no verified business; privacy policy domain (yowgames.com) doesn't match dev email.
  • Content scripts injected on *://*/* (all sites) with no CSP, run as fan-theme shell.

Evidence

  • uninstall_url_hijack crx setUninstallURL → yowgames.com with UTM params; classic monetization shell signal (+3.0 Webstore).
  • install_url_hijack crx onInstalled opens yowgames.com UTM URL; unsolicited 3rd-party navigation on first run (+2.0 Webstore).
  • privacy_policy_fetch_failed api SSLError on yowgames.com/privacy-policy; fetched==false → Privacy pillar +10.0.
  • free_webmail_dev store ayseozkacar237@gmail.com — numbered alias pattern, no verified business; Reputation floor applies.
  • content_scripts_all_urls manifest content_scripts_matches=[*://*/*] injects into every page; broad reach for cursor-only function.
  • no_csp manifest content_security_policy=null on MV3; no runtime CSP protection for injected scripts.
  • jquery_3_6_0_bundled crx jQuery 3.6.0 detected; no CVEs in cve_findings_raw, no CVE pillar penalty.
  • fan_content_shell_pattern store Anime-fan cursor theme with install/uninstall UTM hijack and mismatched dev email vs policy domain.

Permissions Breakdown

  • storage low Stores cursor preference settings locally; expected for this category.
  • content_scripts *://*/* high Injects JS into every page the user visits; broad reach for a cursor extension.

Pillar Scores

Permissions3.00
Reputation7.50
Network2.00
Webstore8.50
Maintenance3.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 16:55
Listing SHA 507a1d58317d…
Force block — not fired
Score recovered no
Elapsed