Balloon Shooter
The AI review rates the findings as likely false positive, but the risk score (44/100) still counts them.
Analysis record
- Analysed
- 2 months ago
- Version
- v0.1.9
- Artifact
- SHA256 205…93D
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
Publisher Evidence
Limited evidencePublisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
Chrome does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.
12 evidence rows available.
Finding Categories
Requested Permissions
1 permissionAI Security Report
AI Security Review
Evidence context: threat category none; evidence quality moderate.
This extension is a simple browser game called "Balloon Shooter" with a clear purpose stated in the description: "Pop balloons by aiming and shooting before time runs out!" The developer uses a Gmail address ([email protected]), which is common for small indie developers but not a verified publisher.
The evidence contains only 4 findings, all categorized as network activity with medium severity. These findings are generic fetch call detections in js/main.js (lines 517, 541, 548) and js/google-analytics.js (line 73). The finding titles "NET-FETCH-js/main.js-517" and similar entries indicate the scanner detected HTTP fetch calls, but critically, no specific suspicious domains or URLs are extracted. The presence of google-analytics.js explicitly indicates legitimate analytics integration, which is standard practice for game extensions to track usage.
There are zero malware signatures, zero obfuscation findings, zero suspicious IoCs, and zero code-smell findings. This is a clean bill of health from a malware detection perspective. The network findings alone—without accompanying suspicious domains or data exfiltration patterns—are insufficient to indicate malicious behavior. Games routinely make network requests to load assets, track analytics, or submit scores.
Counterargument: A skeptic might argue that the Gmail developer email ([email protected]) is suspicious and that any network calls could mask data exfiltration. However, this reasoning is flawed: first, the developer email is not anonymous—it provides a contact point. Second, without evidence of suspicious destination domains in the network findings, claiming data exfiltration is pure speculation. Third, the extension has a coherent game purpose with no behavioral inconsistencies. If this were malicious, we would expect to see malware signatures, obfuscation, or suspicious IoCs alongside the network activity. None exist here.
The findings are consistent with a legitimate game extension making standard HTTP requests. No action is warranted.
Key Reasons
- No malware signatures detected
- No obfuscation findings
- No suspicious domains in network findings
- Clear game purpose with consistent behavior
- Generic fetch calls are normal for game extensions
False Positive Considerations
- Generic fetch call detection without domain extraction
- Google Analytics integration flagged as network activity
- No malware signatures or obfuscation present
Reviewed 2026-04-28; recommended action: no action; model confidence 85%.
Chrome version history
Risk trend by version
4 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace
Level Maze
[email protected]
Table Tennis
[email protected]
Maze
[email protected]
Bridge the Snake
[email protected]
Drag Maze: Back-and-forth Blockers
[email protected]
Unique Triangle Hunt Game
[email protected]