Is KittyCursor - Fun Custom Kitty Cursors safe?

Medium risk

KittyCursor bundles GiveFreely affiliate code that runs on every page and reports the URLs you visit to events.givefreely.com.

Beyond replacing the cursor, this extension injects a GiveFreely shopping/donation app into every page at load and inspects every top-level navigation in the background. It transmits the full page URL (tagged with a persistent random UUID and partner id 'kittycursorext') to events.givefreely.com, and on Google search pages it also sends the search-page URL (which contains your query) plus matched merchant result links. The service worker additionally carries a hardcoded MaxMind license key to look up your country from your IP via geoip.maxmind.com.

chrome-store-publishersv1.3.19Chrome Web Store
45Risk
Who publishes it

Give Freely, LLC - 2 other listings from the same operator, none carrying a finding

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
chrome-store-publishers
Declared legal entity
Give Freely, LLC

Same store account

2 other listings published from this account, 9k+ users between them, none of them carrying a finding.

Shared hosts - 1 hostname

Hostnames hardcoded in this extension that few other listings call. That can mean one operator behind both, and it can equally mean a small shared vendor, so it is context rather than a conclusion. Hosts that many listings call are left out: they are services, not connections.

events.givefreely.com
Also called by 3 other listings, including Tripadvisor: Travel Reviews & Deals on Hotels, Restaurants & Attractions, Companion Window

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

SeverityMEDIUM
ClassUNWANTED
TypeUnexpected
CWECWE-359
SourceAI SANDBOX

KittyCursor sends the domain of merchant sites you visit to GiveFreely

KittyCursor bundles GiveFreely, a third-party affiliate SDK, with a content script and network listener on <all_urls>.

On a merchant-list match, it sends the domain and a persistent device ID to events.givefreely.com, no consent shown.

01EvidenceCAUSE EFFECT
What actually happens
You did this

You navigate to a shopping site the extension recognizes, such as aliexpress.com.

No purchase, click, or interaction with the extension's own UI is required, arriving on the page is enough.

The extension did this

The extension sends that site's domain name and a persistent device identifier to a GiveFreely analytics server.

The request fires from the background service worker within seconds of the page loading, with no visible popup or prompt.

02EvidenceNETWORK CAPTURE
Captured request
POSThttps://events.givefreely.com/popup
HTTP 200 with an empty body on success; the extension logs an error to its own console if the status is anything else.
Headers
Content-Typeapplication/json
Body
{
  "partner": "gfLib_kittyCursors",
  "eventType": "CHECKOUT-POPUP-ACTIVE-DOMAIN",
  "eventData": {
    "userId": "6955e158-9ef7-4c96-869f-93d7f52079d7",
    "libVersion": "2.9.0",
    "url": "aliexpress.com"
  }
}
03EvidenceFIELD TABLE
What the POST to events.givefreely.com/popup contains
FieldValueWhy it matters
Device identifier
6955e158-9ef7-4c96-869f-93d7f52079d7A UUID generated once, stored locally, then attached to every event sent, letting GiveFreely link your visits over time without an account.
Site you visited
aliexpress.comThe domain of the page you're on when it matches GiveFreely's merchant list: activity sent outside the extension's own cursor purpose.
Event type
CHECKOUT-POPUP-ACTIVE-DOMAINA label identifying which internal GiveFreely code path produced this event.
SDK partner ID
kittycursorextIdentifies KittyCursor specifically as the distributing extension inside GiveFreely's partner network.
04EvidenceCODE COMPARE
The code that does this

The content-script gate that fires the domain event

What it actually does
const anonymousActiveDomainLogging = e.popupConfig?.anonymousActiveDomainLogging ?? false;
const activeDomain = t() ?? undefined;

function alreadySentThisSession(domain) {
  const key = `gfhv-${domain}`;
  if (sessionStorage.getItem(key)) return true;
  sessionStorage.setItem(key, "true");
  return false;
}

if (activeDomain && anonymousActiveDomainLogging && !alreadySentThisSession(activeDomain.domain)) {
  Mt.trackEvent(ft.checkoutPopupActiveDomain, { url: activeDomain.domain });
}
05EvidenceCODE COMPARE
The code that does this

The background handler that assembles and sends the request

What it actually does
const STORAGE_KEY = "kui";

const trackEvent = async (eventType, eventData) => {
  let identifier = (await chrome.storage.local.get(STORAGE_KEY))[STORAGE_KEY] || null;
  if (!identifier) {
    identifier = crypto.randomUUID();
    await chrome.storage.local.set({ [STORAGE_KEY]: identifier });
  }
  const body = JSON.stringify({
    identifier,
    partner: "kittycursorext",
    eventType,
    sessionId: "",
    eventData,
  });
  const res = await fetch("https://events.givefreely.com/popup", {
    method: "POST",
    headers: { "Content-Type": "application/json" },
    body,
  });
  if (res.status !== 200) console.error("Error sending analytics event");
};
06EvidenceTHIRD PARTY LIST
Where the data goes
  • events.givefreely.com

    Receives the domain-plus-identifier event on every matched merchant visit. GiveFreely is a third-party affiliate SDK bundled into KittyCursor, not operated by its developer.

  • cdn.givefreely.com

    Serves the merchant-domain list and remote config, including anonymousActiveDomainLogging, that the extension checks every page against.

Where it sends data

Destinations our analysis observed KittyCursor - Fun Custom Kitty Cursors contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.

  • cdn.givefreely.com

    KittyCursor - Fun Custom Kitty Cursors sends data to cdn.givefreely.com. 5 other extensions we have analysed send data here.

  • events.givefreely.com

    KittyCursor - Fun Custom Kitty Cursors sends data to events.givefreely.com. 3 other extensions we have analysed send data here.

  • geoip.maxmind.com

    KittyCursor - Fun Custom Kitty Cursors sends data to geoip.maxmind.com. One other extension we have analysed sends data here.

Updated 30 September 2026aflgglfbbboopfijaiclghbicfckdnfc