Maze
The AI review rates the findings as likely false positive, but the risk score (44/100) still counts them.
Analysis record
- Analysed
- 2 weeks ago
- Version
- v0.4.5
- Artifact
- SHA256 007…E93
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
Publisher Evidence
Limited evidencePublisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
Chrome does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.
12 evidence rows available.
Finding Categories
Requested Permissions
1 permissionAI Security Report
AI Security Review
Evidence context: threat category none; evidence quality strong.
The Maze extension presents a clean security profile with no evidence of malicious behavior. The scan detected only four findings, all limited to network activity. These findings consist of standard fetch calls in js/main.js at lines 333, 361, and 370, plus one fetch call in js/google-analytics.js at line 73. These are expected behaviors for a browser game extension that loads content and tracks usage metrics.
The extension shows zero malware signatures, zero suspicious domain indicators, and zero obfuscation patterns. The code-smell analysis returned no findings, which is notable since most extensions trigger at least some code-smell alerts. The extension's description ("A fun maze game that plays in a popup") aligns with the observed behavior of making network requests for game functionality and analytics. The presence of google-analytics.js is a legitimate tracking library commonly used by developers.
The strongest counterargument would be the generic Gmail developer address ([email protected]) rather than a verified publisher account. However, developer email format alone doesn't indicate malicious intent—many legitimate indie developers use personal Gmail addresses. The actual code behavior is what matters, and there's nothing suspicious in the network calls or code structure. The extension name "Maze" is generic and doesn't impersonate any known extension. With 80,000 users and no red flags in the code, this extension appears to be a legitimate game with standard web functionality.
The findings are driven by the fact that any extension making HTTP requests will trigger network findings. The IoC extractor found zero suspicious domains, and the YARA rules found zero malware signatures. This is the profile of a benign extension, not a threat.
Key Reasons
- Zero malware signatures detected
- Zero suspicious domain IoCs
- Zero obfuscation findings
- Network calls are expected for game functionality and analytics
- Generic name does not impersonate known extensions
False Positive Considerations
- Network findings from standard fetch calls
- Google Analytics integration flagged as network activity
Reviewed 2026-05-23; recommended action: no action; model confidence 85%.
Chrome version history
Risk trend by version
5 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace
Table Tennis
[email protected]
Level Maze
[email protected]
Bubble Eater
[email protected]
Color Pour Puzzle
[email protected]
GameBuddy - Mini Games Anytime
[email protected]
Balloon Shooter
[email protected]