Chrome Web Store

Maze

by [email protected] · 60.0K users · 4.2 rating
dbe7a5d8-999a-5516-93f8-f1941a6ec6f2 | v0.4.5
44/ 100
MEDIUM risk
No change since v0.4.3
Analyst verdict
Review before use

The AI review rates the findings as likely false positive, but the risk score (44/100) still counts them.

Analysis record

Analysed
2 weeks ago
Version
v0.4.5
Artifact
SHA256 007…E93
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

4 detail rows

Publisher Evidence

Limited evidence

[email protected]

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

Chrome does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.

50
Noisy-finding weight
x1.00
Publisher domain
No domain
Missing
Store verification signal
Limited signal
Limited
Extension portfolio
61
Portfolio

12 evidence rows available.

Finding Categories

4
Network

Requested Permissions

1 permission
storage
Low

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality strong.

The Maze extension presents a clean security profile with no evidence of malicious behavior. The scan detected only four findings, all limited to network activity. These findings consist of standard fetch calls in js/main.js at lines 333, 361, and 370, plus one fetch call in js/google-analytics.js at line 73. These are expected behaviors for a browser game extension that loads content and tracks usage metrics.

The extension shows zero malware signatures, zero suspicious domain indicators, and zero obfuscation patterns. The code-smell analysis returned no findings, which is notable since most extensions trigger at least some code-smell alerts. The extension's description ("A fun maze game that plays in a popup") aligns with the observed behavior of making network requests for game functionality and analytics. The presence of google-analytics.js is a legitimate tracking library commonly used by developers.

The strongest counterargument would be the generic Gmail developer address ([email protected]) rather than a verified publisher account. However, developer email format alone doesn't indicate malicious intent—many legitimate indie developers use personal Gmail addresses. The actual code behavior is what matters, and there's nothing suspicious in the network calls or code structure. The extension name "Maze" is generic and doesn't impersonate any known extension. With 80,000 users and no red flags in the code, this extension appears to be a legitimate game with standard web functionality.

The findings are driven by the fact that any extension making HTTP requests will trigger network findings. The IoC extractor found zero suspicious domains, and the YARA rules found zero malware signatures. This is the profile of a benign extension, not a threat.

Key Reasons

  • Zero malware signatures detected
  • Zero suspicious domain IoCs
  • Zero obfuscation findings
  • Network calls are expected for game functionality and analytics
  • Generic name does not impersonate known extensions

False Positive Considerations

  • Network findings from standard fetch calls
  • Google Analytics integration flagged as network activity

Reviewed 2026-05-23; recommended action: no action; model confidence 85%.

Chrome version history

Risk trend by version

5 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
44
Change since first
-7
Change from previous
No change
Versions:
First analyzed version
0.3.8
Jan 28, 2026
Risk range
44 to 50
Across analyzed versions
Latest analyzed version
0.4.5
Aug 3, 2026
Selected version
medium
Version
v0.4.5
1 months ago
Risk score
44
Findings
4
Change vs previous
No change

Pick any point on the chart to explore that version's code below.

About This Extension

Just click the Maze extension icon in the top-right corner of your browser, and the maze opens instantly in a popup! Every maze is randomly generated, so you'll get a new challenge each time you start or restart. Your objective is to guide the red block from the top-left corner to the green block in the bottom-right corner before the 20-second timer runs out. Control the red block using the Arrow keys or WASD. The timer bar at the top shows how much time you have left. When the game ends, press Restart or simply hit Space or Enter to begin a new maze. After the game ends, you can keep going with these optional actions: • Play Next Level – Same classic maze format, but bigger and harder. • Create Competition – Compare your route with the shortest path, then turn this maze into a challenge and invite friends to race through it. • My Competitions – Access all the competitions you've created and see who solved your mazes the fastest. • Try Maze World – Our endless maze adventure with relics, monsters, portals, and changing environments. Enjoy the maze challenge! CHANGELOG ========== Version 0.4.3 - 0.4.5 - Remove featured game list - Add the feature of competitions - Add the link of maze world - Add google analytics on buttons Version 0.3.0 - 0.4.2 - Update the link of the shortest path - Add the link of playing the next level - Dynamic update of featured game list - Add WASD movement support - Prettify code and styles Version 0.2.0 - 0.2.9 - Add the link of bonus features - Add the link of the shortest path - Display featured products after game over Version 0.1.9 - Fix allowing moves after losing - Enable Space/Enter keys to restart Version 0.1.7 - 0.1.8 - Add the section on new games - Update the game list with time Version 0.1.0 - 0.1.6 - Initial release and feature updates

Frequently Asked Questions