Browser SDK and default widget for embedding Pluno Product Agent into customer web apps.
No confirmed malicious attack surface. This is a vendor browser SDK for embedding the Pluno product agent. npm install does not run package code; fetch wrapping, account reads, and helper JavaScript run only after the host mounts the widget and talks to Pluno.
Browser source reuses an authenticated session to collect identity data and mutate account settings while reporting externally.
dist/product-agent-widget.jsView on unpkg · L83After the host mounts the widget, it wraps fetch and XMLHttpRequest and forwards capped host request metadata to the Pluno websocket as network.batch.
dist/product-agent-widget.jsView on unpkg · L11254After the host mounts the widget, it wraps fetch and XMLHttpRequest and forwards capped host request metadata to the Pluno websocket as network.batch.
dist/product-agent-widget.jsView on unpkg · L11568On websocket auth.ok the widget stores server-provided helper JavaScript and can run it with an async Function constructor.
dist/product-agent-widget.jsView on unpkg · L11036On websocket auth.ok the widget stores server-provided helper JavaScript and can run it with an async Function constructor.
dist/product-agent-widget.jsView on unpkg · L11739Account reads use the integrator accountLoader or initialAccount plus Pluno user fields, which the scanner labeled as session hijack.
dist/product-agent-widget.jsView on unpkg · L10573A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/product-agent-runtime.cjs#virtual:string-array:round1View on unpkgpackage.json has no preinstall, install, or postinstall hooks; scripts are build, check, test, and prepack verify only.
package.jsonView on unpkg · L2This report applies to @pluno/product-agent-web@0.1.281.
See version security history for other recorded verdicts.
Evidence last updated: .
Browser source reuses an authenticated session to collect identity data and mutate account settings while reporting externally.
dist/product-agent-widget.jsView on unpkg · L83After the host mounts the widget, it wraps fetch and XMLHttpRequest and forwards capped host request metadata to the Pluno websocket as network.batch.
dist/product-agent-widget.jsView on unpkg · L11254After the host mounts the widget, it wraps fetch and XMLHttpRequest and forwards capped host request metadata to the Pluno websocket as network.batch.
dist/product-agent-widget.jsView on unpkg · L11568On websocket auth.ok the widget stores server-provided helper JavaScript and can run it with an async Function constructor.
dist/product-agent-widget.jsView on unpkg · L11036On websocket auth.ok the widget stores server-provided helper JavaScript and can run it with an async Function constructor.
dist/product-agent-widget.jsView on unpkg · L11739Account reads use the integrator accountLoader or initialAccount plus Pluno user fields, which the scanner labeled as session hijack.
dist/product-agent-widget.jsView on unpkg · L10573A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/product-agent-runtime.cjs#virtual:string-array:round1View on unpkgpackage.json has no preinstall, install, or postinstall hooks; scripts are build, check, test, and prepack verify only.
package.jsonView on unpkg · L2