JSaw Puzzle
The AI review rates the findings as likely false positive, but the risk score (55/100) still counts them.
Analysis record
- Analysed
- 1 weeks ago
- Version
- v1.12
- Artifact
- SHA256 DE1…B7D
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
YARA Rule Matches
8 rules| Severity | Rule | Hits | Files | Metadata |
|---|---|---|---|---|
| LOW | postinstall crypto operations | 10 | tesselations/square.jsfeeds/utils.js_metadata/verified_contents.json +7 more | - |
| LOW | postinstall system command | 4 | jsawpuzzle-ui.jsfeeds/wikimedia-commons-featured.jsfeeds/wikimedia-commons-fetch.js +1 more | - |
| LOW | postinstall file manipulation | 5 | background.jss14e-serializer.jsfeeds/wikimedia-commons-fetch.js +2 more | - |
| LOW | postinstall obfuscation | 2 | s14e-serializer.jsjsawpuzzle-ui.js | - |
| LOW | postinstall network communication | 5 | _locales/en/messages.jsonbackground.jstesselations/rhill-voronoi-core.min.js +2 more | - |
| LOW | postinstall file download | 7 | _locales/en/messages.jsonfeeds/wikimedia-commons-featured.jsfeeds/wikimedia-commons-fetch.js +4 more | - |
| LOW | NoUseWeakRandom | 3 | feeds/wikimedia-commons-featured.jsfeeds/wikimedia-commons-potd.jsfeeds/publicdomainpictures.js | - |
| LOW | LocalStorageShouldNotBeUsed | 1 | jsawpuzzle-ui.js | - |
Network Indicators
Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.
Network indicators are queued for lazy loading
Scroll this section into view to load the detailed rows.
Publisher Evidence
Limited evidencePublisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
Chrome does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.
12 evidence rows available.
Finding Categories
YARA Rules Matched
8 rules(37 hits)Requested Permissions
4 permissionsAI Security Report
AI Security Review
Evidence context: threat category none; evidence quality strong.
Security Analysis: JSaw Puzzle
Extension Overview
JSaw Puzzle is a browser extension described as "Create and solve jigsaw puzzles" published by developer email [email protected]. The extension has 101 users and is currently at version 1.7 on the Chrome Web Store.
Security Findings
The CVEQ analysis returned zero findings across all security categories. The findings_by_category bucket is completely empty, meaning:
- No IoC (Indicators of Compromise) domains or IPs were detected
- No YARA code-smell rules triggered
- No obfuscation patterns were identified
- No malware signatures were found
- No suspicious network behavior was detected
Developer Attribution
The developer email [email protected] belongs to Raymond Hill, the creator of uBlock Origin, one of the most trusted and widely-used ad-blocking extensions. This attribution is a strong positive signal indicating the extension originates from a known, reputable developer in the browser extension ecosystem.
Counterargument Analysis
A skeptic might argue that zero findings could indicate incomplete analysis rather than a genuinely clean extension. However, the evidence bundle contains complete metadata (version number, user count, developer name, store information), which would typically be absent if analysis failed entirely. Furthermore, the extension's functionality (puzzle creation and solving) does not inherently require privileged browser access that would trigger security findings. A legitimate puzzle game extension has no reason to access credentials, modify search engines, or transmit data to external servers, so the absence of findings aligns with expected behavior for this category.
Conclusion
JSaw Puzzle shows no evidence of malicious behavior. The combination of zero security findings and attribution to Raymond Hill (uBlock Origin developer) strongly indicates this is a benign extension. The extension's stated purpose (jigsaw puzzles) is consistent with its lack of network or data access findings. No further action is required.
Key Reasons
- Zero security findings across all categories
- Developer email belongs to Raymond Hill (uBlock Origin creator)
- Extension functionality (puzzle game) does not require suspicious permissions
- No IoC, code-smell, or obfuscation findings detected
False Positive Considerations
- No false positive drivers - genuinely clean extension
- Reputable developer attribution
Reviewed 2026-04-26; recommended action: no action; model confidence 75%.
Chrome version history
Risk trend by version
2 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace
uBlock Origin Lite
Raymond Hill
uBlock Origin Lite
[email protected]
uBlock Origin Scope
[email protected]
Edge Translate - Browser Translator | PDF Translation | MV3 | Open Source
[email protected]
Intelbras Cloud
[email protected]
SlingPlayer for DISH Anywhere
Unknown Developer