Custom Cursor for Chrome
phfkifnjcmdcmljnnablahicoabkokbg
Risk Score
3.27
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- scripting + <all_urls>: can inject code into every site the user visits
- new Function() constructor in 5 files enables dynamic code execution
- No CSP declared (MV3 default applies but no explicit hardening)
- Developer email is free Gmail with no verified business domain linkage
- Privacy policy admits third-party sharing but lacks data retention disclosure
Evidence
- host_permissions=<all_urls> + scripting manifest Can inject arbitrary scripts into every website; high-capability surface.
- function_constructor in 5 JS files crx new Function() pattern present in background, content, injector, options, popup scripts.
- verified_publisher + is_featured_by_google store Both badges present; partially offsets reputation concern from Gmail dev email.
- developer_email=gareilkoberys@gmail.com, no developer_name store Free webmail, no listed developer name — residual reputation risk remains.
- privacy_policy third_party_sharing=true, retention=false api Policy scoped to extension and discloses collection, but omits retention period.
- months_since_update=12 store Borderline 6-12 month staleness band; 800K installs amplify supply-chain risk.
- cve_findings_raw=[], bad_host_hits=[], monetization_hits=[] api No CVEs, no bad hosts, no monetization signals detected.
- obfuscation_score=0.0, no external JS hosts crx Code is not obfuscated and loads no remote scripts; lowers exfil concern.
Permissions Breakdown
- tabs medium Exposes tab URLs and metadata across all open tabs.
- activeTab low Scoped to user-initiated interaction; limited risk alone.
- storage low Local preference storage for cursor settings; standard.
- scripting high Programmatic script injection into pages; paired with <all_urls> elevates risk.
- <all_urls> (host_permissions) high Full cross-origin access to all sites; broadens scripting and tabs risk.
Pillar Scores
Permissions5.50
Reputation3.50
Network2.00
Webstore1.50
Maintenance3.50
Privacy2.00
Code Quality2.50
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 07:57
Listing SHA
76c20c8463f0…
Force block
— not fired
Score recovered
no
Elapsed
—