Is Anime Cursor - Custom Cursor for Chrome™ - All in One Anime Cursors safe?

Medium risk

Anime Cursor fetches remote cursor URLs from api.gameograf.com on every popup open and injects them unsanitized into CSS on all web pages.

Each time the popup is opened, the extension retrieves cursor configuration from api.gameograf.com and stores the returned URLs directly in chrome.storage without sanitization. A content script running on all web pages then reads those URLs and substitutes them into a CSS template using innerHTML, meaning a malicious or compromised remote response could inject arbitrary CSS rules into every page the user visits.

Part of this rating comes from analysis signals we haven't published as detailed findings yet.

Gameografv1.0.2Chrome Web Store
45Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Updated 17 September 2026kbgpgmcbehkiiooamcldaccehdcdenmn