When the frictionless CAPTCHA flow runs, provider-controlled JavaScript is fetched and executed in the embedding page. This is a remote-code-execution capability with access to inputs supplied by the widget.
Package source references dynamic require/import behavior.
dist/detectorLoader.jsView on unpkg · L4Package metadata claims a different repository identity while copied source loads a runtime dependency bridge.
dist/cjs/customDetectBot.cjsView on unpkg · L3A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
src/customDetectBot.ts#virtual:normalized:round1View on unpkgThe package obtains a detector script from a selected provider at runtime.
src/customDetectBot.tsView on unpkg · L225It turns that provider-supplied string into a Blob module and dynamically imports it, executing remote code in the host browser.
src/detectorLoader.tsView on unpkg · L67This report applies to @prosopo/procaptcha-frictionless@2.14.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Package source references dynamic require/import behavior.
dist/detectorLoader.jsView on unpkg · L4A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
src/customDetectBot.ts#virtual:normalized:round1View on unpkgPackage metadata claims a different repository identity while copied source loads a runtime dependency bridge.
dist/cjs/customDetectBot.cjsView on unpkg · L3The package obtains a detector script from a selected provider at runtime.
src/customDetectBot.tsView on unpkg · L225It turns that provider-supplied string into a Blob module and dynamically imports it, executing remote code in the host browser.
src/detectorLoader.tsView on unpkg · L67