Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Pusheen Cursor - Custom Kawaii Cursor for Chrome

pjfjconkopcckeanlhklghfogkdhnegk
Risk Score
4.43
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Entertainment
Installs 1,000
Rating 4.8
Last updated 2026-06-28 (3 months ago)
Manifest version MV3
CSP present ❌ no
Developer info@tabplugins.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Uninstall and install URL hijacks redirect users to tabplugins.com marketing pages — monetization shell pattern.
  • scripting + *://*/* grants full code injection into every site; broad capability for a cursor extension.
  • Privacy policy admits data collection and third-party sharing but lacks retention disclosure.
  • No CSP (MV3 default applies but no explicit policy) combined with DOM-XSS innerHTML sink in main JS.
  • Developer domain tabplugins.com is only ~495 days old (first cert 2025-05-07); low-history operator.

Evidence

  • install_url_hijack crx onInstalled opens tabplugins.com marketing URL — monetization redirect on install.
  • uninstall_url_hijack crx setUninstallURL points to tabplugins.com/cursors — 3rd-party uninstall redirect.
  • host_permissions_broad manifest host_permissions *://*/* combined with scripting enables injection on every site visited.
  • dom_sink_innerhtml_userctrl crx innerHTML sink in main.4964ab1e.js; no CSP to mitigate DOM-XSS risk.
  • privacy_policy_gaps store Policy fetched; data_collection=true, third_party_sharing=true, retention=false.
  • domain_age api tabplugins.com first cert 2025-05-07, age_days=495; relatively new operator domain.
  • no_verified_publisher store Not verified, not featured; developer WallExt has no recognized org status.
  • install_and_uninstall_hijack_pattern manifest Both install and uninstall URL hijacks present — classic low-effort traffic-monetization cluster.

Permissions Breakdown

  • storage low Stores cursor preferences locally; standard low-risk API.
  • unlimitedStorage low Allows larger local storage; minor risk for a cursor extension.
  • scripting high Enables dynamic script injection into any page via host_permissions *://*/*.
  • *://*/* (host_permissions) high Grants scripting and content-script access to every URL visited by the user.

Pillar Scores

Permissions6.00
Reputation5.50
Network3.50
Webstore7.00
Maintenance0.00
Privacy2.00
Code Quality2.50
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-15 12:00
Listing SHA acb091061717…
Force block — not fired
Score recovered no
Elapsed