Browser SDK and default widget for embedding Pluno Product Agent into customer web apps.
This is a customer-mounted Pluno chat SDK. The high scanner labels match documented host token-endpoint cookie use, account presentation, and page network capture for the product agent, not an install-time or covert hijack.
Browser source reuses an authenticated session to collect identity data and mutate account settings while reporting externally.
dist/product-agent-widget.jsView on unpkg · L83The widget posts the page origin and URL to an integrator token endpoint with credentials include, which is the session-reuse pattern the scanner labeled as account hijack.
dist/product-agent-widget.jsView on unpkg · L21456After init, the SDK patches fetch and XMLHttpRequest and forwards capped host network events to the Pluno product-agent socket.
dist/product-agent-widget.jsView on unpkg · L11096After init, the SDK patches fetch and XMLHttpRequest and forwards capped host network events to the Pluno product-agent socket.
dist/product-agent-widget.jsView on unpkg · L11105After init, the SDK patches fetch and XMLHttpRequest and forwards capped host network events to the Pluno product-agent socket.
dist/product-agent-widget.jsView on unpkg · L9118A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/product-agent-runtime.cjs#virtual:string-array:round1View on unpkgThe widget posts the page origin and URL to an integrator token endpoint with credentials include, which is the session-reuse pattern the scanner labeled as account hijack.
package.jsonView on unpkg · L1The widget posts the page origin and URL to an integrator token endpoint with credentials include, which is the session-reuse pattern the scanner labeled as account hijack.
package.jsonView on unpkg · L33This report applies to @pluno/product-agent-web@0.1.270.
See version security history for other recorded verdicts.
Evidence last updated: .
Browser source reuses an authenticated session to collect identity data and mutate account settings while reporting externally.
dist/product-agent-widget.jsView on unpkg · L83The widget posts the page origin and URL to an integrator token endpoint with credentials include, which is the session-reuse pattern the scanner labeled as account hijack.
dist/product-agent-widget.jsView on unpkg · L21456After init, the SDK patches fetch and XMLHttpRequest and forwards capped host network events to the Pluno product-agent socket.
dist/product-agent-widget.jsView on unpkg · L11096After init, the SDK patches fetch and XMLHttpRequest and forwards capped host network events to the Pluno product-agent socket.
dist/product-agent-widget.jsView on unpkg · L11105After init, the SDK patches fetch and XMLHttpRequest and forwards capped host network events to the Pluno product-agent socket.
dist/product-agent-widget.jsView on unpkg · L9118A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/product-agent-runtime.cjs#virtual:string-array:round1View on unpkgThe widget posts the page origin and URL to an integrator token endpoint with credentials include, which is the session-reuse pattern the scanner labeled as account hijack.
package.jsonView on unpkg · L1The widget posts the page origin and URL to an integrator token endpoint with credentials include, which is the session-reuse pattern the scanner labeled as account hijack.
package.jsonView on unpkg · L33