Chrome Web Store

Level Maze

by [email protected] · 10.0K users · 4.6 rating
3c49724f-e835-5dd7-a666-8ac10da52bf3 | v0.3.5
44/ 100
MEDIUM risk
No change since v0.3.4
Analyst verdict
Review before use

The AI review rates the findings as likely false positive, but the risk score (44/100) still counts them.

Analysis record

Analysed
2 weeks ago
Version
v0.3.5
Artifact
SHA256 9C0…9D8
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

4 detail rows

Publisher Evidence

Limited evidence

[email protected]

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

Chrome does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.

45
Noisy-finding weight
x1.00
Publisher domain
No domain
Missing
Store verification signal
Limited signal
Limited
Extension portfolio
61
Portfolio

12 evidence rows available.

Finding Categories

4
Network

Requested Permissions

1 permission
storage
Low

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality strong.

Level Maze is a browser game extension that plays a level-up maze in a popup window. The security analysis reveals no evidence of malicious behavior.

Network Activity: Four medium-severity network findings were detected across the codebase. These are all generic fetch calls located at js/main.js:121, js/main.js:149, js/main.js:158, and js/google-analytics.js:73. Importantly, no suspicious domains or URLs were extracted from these network calls. The presence of google-analytics.js indicates legitimate analytics tracking, which is common for game extensions to monitor user engagement.

Malware Signatures: Zero malware signatures matched any files in the extension. This is a critical finding that strongly indicates clean code.

Obfuscation: No obfuscation was detected in any files. The code is readable and does not employ techniques commonly used to hide malicious behavior.

Code Quality: No code-smell patterns were identified. The extension does not contain suspicious patterns like credential harvesting, suspicious API key usage, or other red-flag behaviors.

Suspicious Domains: The IoC extractor found zero suspicious domains, IPs, or URLs. All network activity appears to be standard fetch calls without any connection to known malicious infrastructure.

Counterargument: The strongest concern a skeptic might raise is the developer identity: [email protected] is a generic Gmail address rather than a verified publisher account. Anonymous developers do warrant scrutiny. However, with 10,000 users, zero malware signatures, zero suspicious domains, and code that matches the stated purpose (a maze game), the risk profile is minimal. The network findings are expected behavior for any extension that communicates with servers, and the absence of actual malicious indicators outweighs the anonymity concern.

Conclusion: This extension exhibits the profile of a legitimate browser game. The findings are noise from generic network detection rules triggering on normal fetch calls. No evidence of malicious intent or capability was found.

Key Reasons

  • Zero malware signatures detected
  • No suspicious domains or IoCs extracted
  • No obfuscation in codebase
  • Network findings are generic fetch calls without malicious destinations
  • Extension behavior matches stated purpose (maze game)

False Positive Considerations

  • Generic fetch calls triggering network detection rules
  • No suspicious domains extracted despite network findings
  • Zero malware signatures matched
  • No obfuscation or code-smell patterns detected

Reviewed 2026-05-23; recommended action: suppress false positive; model confidence 85%.

Chrome version history

Risk trend by version

3 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
44
Change since first
No change
Change from previous
No change
Versions:
First analyzed version
0.3.3
Apr 9, 2026
Risk range
44 to 44
Across analyzed versions
Latest analyzed version
0.3.5
Aug 7, 2026
Selected version
medium
Version
v0.3.5
1 months ago
Risk score
44
Findings
4
Change vs previous
No change

Pick any point on the chart to explore that version's code below.

About This Extension

The play is very simple, just move the top-left red block to touch the green block at the bottom right corner in the given time (20s). Use the Arrow keys or WASD to move and keep an eye on the timer bar at the top of the maze to see how much time you have left. Only when you win current game, you can go to next level. If you want to go back to level 1, just click reset button when current game is over. Try to challenge yourself to see if you can win at the level of 10 or higher (really hard!!!). The maze is randomly generated based on current difficulty level and the map will be different each time the game starts. Have fun with the maze game! To discover the shortest path, click the link located below the 'Restart' button. To enjoy even more, check out some of our featured game extensions on the game over page. CHANGELOG ========== Version 0.2.3 - 0.3.5 - Update the link of the shortest path - Enable dynamic update of featured games - Add WASD movement support - Prettify code and styles Version 0.1.8 - 0.2.2 - Add the link of bonus features - Add the link of the shortest path - Display featured games after game over Version 0.1.7 - Fix allowing moves after losing - Enable Space/Enter keys for next level Version 0.1.3 - 0.1.6 - Add the section of new games - Update new game list with time - Update level maze icon Version 0.1.0 - 0.1.2 - Initial release of maze game - Improve interface and features

Frequently Asked Questions