Pusheen Cursor - Custom Kawaii Cursor for Chrome
pjfjconkopcckeanlhklghfogkdhnegk
Risk Score
4.43
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Uninstall and install URL hijacks redirect users to tabplugins.com marketing pages — monetization shell pattern.
- scripting + *://*/* grants full code injection into every site; broad capability for a cursor extension.
- Privacy policy admits data collection and third-party sharing but lacks retention disclosure.
- No CSP (MV3 default applies but no explicit policy) combined with DOM-XSS innerHTML sink in main JS.
- Developer domain tabplugins.com is only ~495 days old (first cert 2025-05-07); low-history operator.
Evidence
- install_url_hijack crx onInstalled opens tabplugins.com marketing URL — monetization redirect on install.
- uninstall_url_hijack crx setUninstallURL points to tabplugins.com/cursors — 3rd-party uninstall redirect.
- host_permissions_broad manifest host_permissions *://*/* combined with scripting enables injection on every site visited.
- dom_sink_innerhtml_userctrl crx innerHTML sink in main.4964ab1e.js; no CSP to mitigate DOM-XSS risk.
- privacy_policy_gaps store Policy fetched; data_collection=true, third_party_sharing=true, retention=false.
- domain_age api tabplugins.com first cert 2025-05-07, age_days=495; relatively new operator domain.
- no_verified_publisher store Not verified, not featured; developer WallExt has no recognized org status.
- install_and_uninstall_hijack_pattern manifest Both install and uninstall URL hijacks present — classic low-effort traffic-monetization cluster.
Permissions Breakdown
- storage low Stores cursor preferences locally; standard low-risk API.
- unlimitedStorage low Allows larger local storage; minor risk for a cursor extension.
- scripting high Enables dynamic script injection into any page via host_permissions *://*/*.
- *://*/* (host_permissions) high Grants scripting and content-script access to every URL visited by the user.
Pillar Scores
Permissions6.00
Reputation5.50
Network3.50
Webstore7.00
Maintenance0.00
Privacy2.00
Code Quality2.50
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-15 12:00
Listing SHA
acb091061717…
Force block
— not fired
Score recovered
no
Elapsed
—