CRX aminer
Extension icon

Hello Kitty Cursor - Custom Kawaii Cursor for Chrome

Version 1.0.3 View in Chrome Web Store

Last scanned: 21 days ago | force re-scan

Extension Details

Rating: 3.9 ★ (9 ratings)
Users: 6,000

Context-Aware Verdict

HIGH
Overall Risk
Trust Factors: The extension has a modest user base of 6,000 users with a decent 3.9-star rating, though based on only 9 reviews which is quite limited for assessment. The lack of clear developer information and company details reduces trustworthiness. The extension's purpose as a cursor customization tool seems legitimate and appeals to users interested in kawaii/cute aesthetics.
Concerns: The extension requests extremely broad permissions that are disproportionate to its stated function of changing cursors. The combination of universal host permissions (*://*/*) and content script injection capabilities across all websites creates significant security risks. A simple cursor customization tool should not need to access and potentially modify content on every website you visit. The storage and unlimited storage permissions, while less concerning individually, compound the risk when combined with the broad access capabilities.
Recommendations: Consider running this extension in a separate Chrome profile dedicated to non-sensitive browsing if you must use it. Alternatively, look for cursor customization extensions with more limited permissions that only affect specific sites or use different approaches that don't require broad web access. Monitor your browsing behavior and be cautious about visiting sensitive sites (banking, email, social media) while this extension is active. The risk-to-benefit ratio appears unfavorable given the extensive permissions for such a simple cosmetic feature.

Findings

HIGH
Broad Content Script Injection
This extension can inject scripts into any website. This means it could potentially read sensitive data, modify website content, or steal credentials.
HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.
MEDIUM
Medium-Risk Permission: unlimitedStorage
This extension has the unlimitedStorage permission. Can store unlimited data locally.