Security Warning: High Security Risk
Game Over
ID: cljiolbjehnoaeohbnefccjecpikfbai
Supported Languages
Extension Info & Metadata
Publisher Contextual Analysis
- Author
- pettyexploitsView Profile
- Privacy
- Privacy Policy
- MX records exist
- Yes
- Domain exists
- Yes
- Is disposable
- No
- Is role-based
- No
- Mailbox exists
- Yes
A comprehensive security and academic integrity tool
Made this on a whim to keep students trying to play .html games in a school environment on track 10/15/24 *Added popup window when clicking the extension, as well as updating the redirected site* 10/22/24 *Fixed it so it also redirects websites as well as local files* 11/6/24 *Revamped the whole thing, gave it a much simpler approach as well as added an admin menu and a hardcoded whitelist with the ability to manually add urls to temporarily unblock a site* 4/30/25 *Added wss blocking for eaglercraft's relay servers *Added fingerprinting for time wasting code pasted into compilers 5/1/25 *Added toggle checkboxes to disable .html/.mhtml, fingerprintint and wss blocking features* *Updated blocking messages* *Updated whitelists* 5/2/25 *More whitelist adjustments and some back end work so whitelist syncs up before blocking rules take effect* 5/5/25 *Hopefully fixed local .html files from being loaded* *Whitelist hopefully loads again now* 5/8/25 *added paste interceptor to replace proxy/game copy pasta with an ascii image* 5/19/25 *Upgraded from local .html to fingerprinting proxy/game code and has a working copy/paste replacer if it finds certain keywords. Added checkboxes in the admin panel to enable/disable certain functions* 5/29/25 *Added admin logging panel to help debug, and whitelist false positives. Also fixed colors in light mode for the weirdos who aren't using darkmode*
The bundled ZIP manifest declares only 'declarativeNetRequest' and 'storage', but the live CWS listing additionally declares 'scripting', 'clipboardWrite', 'webNavigation', 'declarativeNetRequestFeedback', and 'file://*/*', plus content scripts. The 'scripting' permission in particular grants executeScript capability (arbitrary JS injection into pages) that is entirely absent from the reviewed code. This discrepancy means the installed live extension has substantially broader capabilities than the version audited here, and those capabilities are unaccounted for by this review.
{ "permissions": [ "declarativeNetRequest", "storage" ], "host_permissions": [ "<all_urls>" ]}By severity
Versions scanned
None of the 35 scanned versions have more than one unique code-review finding. Counts are unique findings that include each version.
| Extension Version | Code Review Findings |
|---|---|
| No versions with multiple unique findings. | |
Files with findings
1 distinct path β top paths by unique finding count:
- manifest.json1
URLs
View the external URLs this extension communicates with to understand its network activity and data interactions.
Gain full insight into all external connections.
Upgrade for full visibility.
Gain full insight into all external connections.
Upgrade for full visibility.
Code Diff
Compare extension code between any two versions.
No comparable text files found between these versions.
Browse and explore files within this extension package
Gain full insight into all external connections.
Upgrade for full visibility.