2048 Classic Game
kgfeiebnfmmfpomhochmlfmdmjmfedfj
Risk Score
5.53
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Game extension claims <all_urls> host access and injects content scripts on every site — severe capability mismatch.
- Privacy policy is Google's generic account policy; scope_extension=false, data_collection=true, third_party_sharing=true — worst-case Privacy score.
- Developer uses free Gmail with no business presence; unverified identity for an extension with broad access.
- External JS host includes github.com alongside Google Analytics — no CSP to constrain remote loading.
- is_featured_by_google=true but broad permissions + generic privacy policy still present significant residual risk.
Evidence
- broad_host_access_mismatch manifest <all_urls> host_permissions + content_scripts on all URLs declared for a simple 2048 game — clear scope mismatch.
- generic_privacy_policy store Privacy policy points to Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
- free_webmail_developer store Developer email matthewwatson24648@gmail.com; no business domain; no verified publisher badge.
- external_js_hosts crx JS contacts github.com and www.google-analytics.com; no CSP present on MV3 extension.
- google_analytics_telemetry api monetization_hits: google-analytics telemetry; only telemetry-tier hit, single domain.
- featured_by_google store is_featured_by_google=true; provides partial trust discount but not verified publisher.
- no_cve_findings crx cve_findings_raw empty; no known vulnerable libraries bundled.
- maintenance_3_6_months store months_since_update=6; borderline 3-6 month stale band; +1.5 maintenance score.
Permissions Breakdown
- storage low Stores game state locally; low risk.
- scripting medium Can inject scripts into pages; medium risk without broader context.
- alarms low Schedules background tasks; low risk.
- <all_urls> (host_permissions) high Broad host access on all URLs; mismatched for a game extension.
- <all_urls> (content_scripts) high Content scripts injected on every site; high capability for a game.
Pillar Scores
Permissions7.00
Reputation6.50
Network4.00
Webstore5.50
Maintenance1.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 07:58
Listing SHA
ca0b8f556d5f…
Force block
— not fired
Score recovered
no
Elapsed
—