Is KittyCursor - Fun Custom Kitty Cursors safe?
KittyCursor bundles GiveFreely affiliate code that runs on every page and reports the URLs you visit to events.givefreely.com.
Beyond replacing the cursor, this extension injects a GiveFreely shopping/donation app into every page at load and inspects every top-level navigation in the background. It transmits the full page URL (tagged with a persistent random UUID and partner id 'kittycursorext') to events.givefreely.com, and on Google search pages it also sends the search-page URL (which contains your query) plus matched merchant result links. The service worker additionally carries a hardcoded MaxMind license key to look up your country from your IP via geoip.maxmind.com.
Who publishes itGive Freely, LLC - 2 other listings from the same operator, none carrying a finding
Give Freely, LLC - 2 other listings from the same operator, none carrying a finding
What this publisher told the store about itself, and the other listings that told it the same thing.
Same store account
2 other listings published from this account, 9k+ users between them, none of them carrying a finding.
Shared hosts - 1 hostname
Hostnames hardcoded in this extension that few other listings call. That can mean one operator behind both, and it can equally mean a small shared vendor, so it is context rather than a conclusion. Hosts that many listings call are left out: they are services, not connections.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
Findings
KittyCursor sends the domain of merchant sites you visit to GiveFreely
KittyCursor bundles GiveFreely, a third-party affiliate SDK, with a content script and network listener on <all_urls>.
On a merchant-list match, it sends the domain and a persistent device ID to events.givefreely.com, no consent shown.
You navigate to a shopping site the extension recognizes, such as aliexpress.com.
No purchase, click, or interaction with the extension's own UI is required, arriving on the page is enough.
The extension sends that site's domain name and a persistent device identifier to a GiveFreely analytics server.
The request fires from the background service worker within seconds of the page loading, with no visible popup or prompt.
| Content-Type | application/json |
{
"partner": "gfLib_kittyCursors",
"eventType": "CHECKOUT-POPUP-ACTIVE-DOMAIN",
"eventData": {
"userId": "6955e158-9ef7-4c96-869f-93d7f52079d7",
"libVersion": "2.9.0",
"url": "aliexpress.com"
}
}| Field | Value | Why it matters | |
|---|---|---|---|
Device identifier | 6955e158-9ef7-4c96-869f-93d7f52079d7 | A UUID generated once, stored locally, then attached to every event sent, letting GiveFreely link your visits over time without an account. | |
Site you visited | aliexpress.com | The domain of the page you're on when it matches GiveFreely's merchant list: activity sent outside the extension's own cursor purpose. | |
Event type | CHECKOUT-POPUP-ACTIVE-DOMAIN | A label identifying which internal GiveFreely code path produced this event. | |
SDK partner ID | kittycursorext | Identifies KittyCursor specifically as the distributing extension inside GiveFreely's partner network. |
The content-script gate that fires the domain event
const anonymousActiveDomainLogging = e.popupConfig?.anonymousActiveDomainLogging ?? false;
const activeDomain = t() ?? undefined;
function alreadySentThisSession(domain) {
const key = `gfhv-${domain}`;
if (sessionStorage.getItem(key)) return true;
sessionStorage.setItem(key, "true");
return false;
}
if (activeDomain && anonymousActiveDomainLogging && !alreadySentThisSession(activeDomain.domain)) {
Mt.trackEvent(ft.checkoutPopupActiveDomain, { url: activeDomain.domain });
}The background handler that assembles and sends the request
const STORAGE_KEY = "kui";
const trackEvent = async (eventType, eventData) => {
let identifier = (await chrome.storage.local.get(STORAGE_KEY))[STORAGE_KEY] || null;
if (!identifier) {
identifier = crypto.randomUUID();
await chrome.storage.local.set({ [STORAGE_KEY]: identifier });
}
const body = JSON.stringify({
identifier,
partner: "kittycursorext",
eventType,
sessionId: "",
eventData,
});
const res = await fetch("https://events.givefreely.com/popup", {
method: "POST",
headers: { "Content-Type": "application/json" },
body,
});
if (res.status !== 200) console.error("Error sending analytics event");
};- events.givefreely.com
Receives the domain-plus-identifier event on every matched merchant visit. GiveFreely is a third-party affiliate SDK bundled into KittyCursor, not operated by its developer.
- cdn.givefreely.com
Serves the merchant-domain list and remote config, including anonymousActiveDomainLogging, that the extension checks every page against.
Where it sends data
Destinations our analysis observed KittyCursor - Fun Custom Kitty Cursors contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.
- cdn.givefreely.com
KittyCursor - Fun Custom Kitty Cursors sends data to cdn.givefreely.com. 5 other extensions we have analysed send data here.
- events.givefreely.com
KittyCursor - Fun Custom Kitty Cursors sends data to events.givefreely.com. 3 other extensions we have analysed send data here.
- geoip.maxmind.com
KittyCursor - Fun Custom Kitty Cursors sends data to geoip.maxmind.com. One other extension we have analysed sends data here.