Is 2048 safe?

Medium risk

2048 collects the user's Google account email and sends it as a player identifier to its game servers, including over plain HTTP.

When a user signs in or starts a game, the extension requests the identity.email permission and retrieves the account email address using chrome.identity.getProfileUserInfo(). This email is stored and sent without hashing or anonymization to beta.apihub.info and data.apihub.info as a URL query parameter and POST body field, used to track leaderboard scores and account stats. Some of these requests are made over plain HTTP rather than HTTPS.

Part of this rating comes from analysis signals we haven't published as detailed findings yet.

molokov1.1.0.53Chrome Web Store
45Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

What it can do

Permissions this extension asks for, as declared in version 1.1.0.53. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Store data in your browser

    storage

Where it sends data

Destinations our analysis observed 2048 contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.

  • data.apihub.info

    2048 sends data to data.apihub.info. One other extension we have analysed sends data here.

  • beta.apihub.info

    2048 sends data to beta.apihub.info. No other extension we have analysed sends data here.

Updated 30 September 2026ijkmjnaahlnmdjjlbhbjbhlnmadmmlgg