Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Attack on Titan Cursor - Custom Anime Cursor for Chrome

pgmiigclfodaendfgenfbmcfoefaljda
Risk Score
4.47
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Entertainment
Installs 516
Rating
Last updated 2026-06-21 (3 months ago)
Manifest version MV3
CSP present ❌ no
Developer info@tabplugins.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Uninstall + install URL hijack to developer's own marketing pages — clear monetization-redirect pattern.
  • scripting + *://*/*ホスト access lets extension inject code on every page the user visits.
  • Privacy policy discloses data collection and third-party sharing but lacks retention period.
  • No developer name listed; low-install extension with HIGH-tier host permissions (tail attack surface).
  • No CSP declared (MV3 default mitigates, but innerHTML sink present in bundled React code).

Evidence

  • uninstall_url_hijack manifest setUninstallURL points to tabplugins.com marketing page; +3.0 webstore.
  • install_url_hijack manifest onInstalled opens tabplugins.com promo URL; +2.0 webstore.
  • host_permissions_broad manifest *://*/* paired with scripting — can read/modify all pages.
  • privacy_policy_third_party_sharing api Policy admits data collection + third-party sharing; no retention disclosed.
  • install_perm_anomaly store 516 installs with HIGH-tier host permission — small-install high-perm flag.
  • dom_sink_innerhtml crx innerHTML sink in main bundle (React internals); no CSP to mitigate.
  • no_developer_name store developer_name is empty string; reduces accountability.
  • verified_publisher store tabplugins.com verified publisher; -3.0 reputation discount (floored at 2.0 cap).

Permissions Breakdown

  • storage low Standard key-value storage for extension settings.
  • unlimitedStorage low Allows larger local storage quota; low risk alone.
  • scripting medium Allows programmatic injection of scripts into pages; elevated when paired with *://*/*.
  • *://*/* (host_permissions) high Broad host access across all sites; enables scripting content on every page visited.

Pillar Scores

Permissions6.00
Reputation4.50
Network2.00
Webstore7.50
Maintenance0.00
Privacy2.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-15 11:57
Listing SHA a2f5268d2bbf…
Force block — not fired
Score recovered no
Elapsed