Chrome Web Store

Bridge the Snake

by [email protected] · 1.0K users · 4.5 rating
0000f1a0-cb34-5526-8277-dc58e1690f07 | v0.1.3
54/ 100
MEDIUM risk
No change since v0.1.2
Risk verdict
Review before use

Score-based assessment (medium risk, 54/100). No analyst review available.

Analysis record

Analysed
6 months ago
Version
v0.1.3
Artifact
SHA256 47A…3DB
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

9 detail rows

YARA Rule Matches

5 rules
SeverityRuleHitsFilesMetadata
LOWpostinstall file download 2
js/main.jsjs/google-analytics.js
-
LOWpostinstall crypto operations 2
_metadata/verified_contents.jsonjs/google-analytics.js
-
LOWpostinstall obfuscation 1
manifest.json
-
LOWpostinstall network communication 1
js/google-analytics.js
-
LOWLocalStorageShouldNotBeUsed 1
js/main.js
-

Network Indicators

Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.

13 total
...

Network indicators are queued for lazy loading

Scroll this section into view to load the detailed rows.

Publisher Evidence

Limited evidence

[email protected]

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

Chrome does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.

39
Noisy-finding weight
x1.00
Publisher domain
No domain
Missing
Store verification signal
Limited signal
Limited
Extension portfolio
61
Portfolio

12 evidence rows available.

Finding Categories

2
Network
13
IoC Indicators

YARA Rules Matched

5 rules(7 hits)
postinstall file download postinstall crypto operations postinstall obfuscation postinstall network communication LocalStorageShouldNotBeUsed

Requested Permissions

1 permission
storage
Low

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality strong.

This extension is a simple Snake game with zero security findings detected across all categories. The findings_by_category object is completely empty, indicating no malicious code patterns, suspicious domains, obfuscation, or credential access were identified during analysis. The extension description 'Eat apples and cross the river using scattered stones as your bridge!' clearly describes classic arcade game functionality with no indication of data collection, browser hijacking, or third-party communication.

The developer uses a generic Gmail address ([email protected]), which is common for indie game developers but lacks corporate verification. With 1000 users and version 0.1.3, this appears to be a small-scale personal project rather than a commercial extension. The extension name 'Bridge the Snake' is descriptive of its gameplay mechanics and does not impersonate any known legitimate extension.

A skeptic might argue that the empty findings object could indicate incomplete analysis rather than a clean scan. However, the evidence bundle shows the extension was processed by CVEQ with a specific UUID (0000f1a0-cb34-5526-8277-dc58e1690f07) and version number (0.1.3), suggesting the analysis completed successfully. The absence of findings for a simple game extension is expected behavior - Snake games typically contain minimal JavaScript with no network requests, no credential access, and no external dependencies that would trigger security rules. If CVEQ's scoring system flags this extension, it would be due to known false-positive drivers like the generic email developer or low user count, not actual malicious behavior.

The extension poses no identified threat. Any automated risk scoring would be based on non-malicious factors rather than security findings.

Key Reasons

  • Zero security findings across all categories
  • Clear benign game functionality in description
  • No suspicious domains or network behavior detected
  • No obfuscation or code-smell patterns identified
  • Simple game extension with no data access capabilities

False Positive Considerations

  • Generic email developer address
  • Low user count (1000 users)
  • Unverified publisher identity

Reviewed 2026-04-23; recommended action: no action; model confidence 85%.

Chrome version history

Risk trend by version

2 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
54
Change since first
No change
Change from previous
No change
Versions:
First analyzed version
0.1.2
Mar 9, 2026
Risk range
54 to 54
Across analyzed versions
Latest analyzed version
0.1.3
Apr 2, 2026
Selected version
medium
Version
v0.1.3
6 months ago
Risk score
54
Findings
22
Change vs previous
0

Pick any point on the chart to explore that version's code below.

About This Extension

Bridge the Snake is a level-based puzzle game where you guide a snake across a river by stepping on scattered stones. To advance to next level, you must collect all the apples and reach the exit on the right. The key strategy: eat apples to grow longer, then use your extended body to reach apples placed in hard-to-reach spots over the river. How to Play? • Use arrow keys to control the snake. • Stay on floating stones to cross the river safely. • Collect all apples to unlock the exit. • Each apple extends the snake’s length. • Falling into the water ends the level. Game Features: • 10 progressively challenging levels. • "Retry" to replay the current level or "Restart" from Level 1. • Strategic movement and planning required to avoid falling. Tips for Success: • Always keep part of the snake on a stone. • Some apples are tricky — plan your path carefully. • You may need to cross back and forth to succeed. Can you beat all 10 levels and master the river?

Frequently Asked Questions