为漫画站增加双页阅读、翻译等优化体验的增强功能的油猴脚本
When the userscript runs on hdoujin.org, it obtains an image base URL from api.hdoujin.org and forwards the page cookie to that returned base. The unrestricted cross-origin grant leaves the receiver insufficiently constrained.
Package source references dynamic require/import behavior.
ComicReader.umd.jsView on unpkg · L5Package source references a known benign dynamic code generation pattern.
ComicReader.umd.jsView on unpkg · L15Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
ComicRead-AdGuard.user.jsView on unpkgThe userscript requests unrestricted cross-origin access and GM_xmlhttpRequest.
ComicRead-AdGuard.user.jsView on unpkg · L93On hdoujin.org, it sends document.cookie to a base URL supplied by a remote API response.
ComicRead-AdGuard.user.jsThis report applies to @hymbz/comic-read-script@12.11.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Package source references dynamic require/import behavior.
ComicReader.umd.jsView on unpkg · L5Package source references a known benign dynamic code generation pattern.
ComicReader.umd.jsView on unpkg · L15Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
ComicRead-AdGuard.user.jsView on unpkgThe userscript requests unrestricted cross-origin access and GM_xmlhttpRequest.
ComicRead-AdGuard.user.jsView on unpkg · L93On hdoujin.org, it sends document.cookie to a base URL supplied by a remote API response.
ComicRead-AdGuard.user.js