The browser runtime downloads an opaque detector script from the selected captcha provider and evaluates it as a blob module. It also fetches a provider-supplied observation URL without credentials.
Package source references dynamic require/import behavior.
dist/detectorLoader.jsView on unpkg · L4Package metadata claims a different repository identity while copied source loads a runtime dependency bridge.
dist/cjs/customDetectBot.cjsView on unpkg · L3A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
src/customDetectBot.ts#virtual:normalized:round1View on unpkgDuring normal captcha use, the package obtains a provider-supplied detector script and passes it to a loader for execution.
src/customDetectBot.tsView on unpkg · L225During normal captcha use, the package obtains a provider-supplied detector script and passes it to a loader for execution.
src/detectorLoader.tsView on unpkg · L67This report applies to @prosopo/procaptcha-frictionless@2.13.22.
See version security history for other recorded verdicts.
Evidence last updated: .
Package source references dynamic require/import behavior.
dist/detectorLoader.jsView on unpkg · L4A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
src/customDetectBot.ts#virtual:normalized:round1View on unpkgPackage metadata claims a different repository identity while copied source loads a runtime dependency bridge.
dist/cjs/customDetectBot.cjsView on unpkg · L3During normal captcha use, the package obtains a provider-supplied detector script and passes it to a loader for execution.
src/customDetectBot.tsView on unpkg · L225During normal captcha use, the package obtains a provider-supplied detector script and passes it to a loader for execution.
src/detectorLoader.tsView on unpkg · L67