Mounting the CAPTCHA can request a detector bundle from a selected provider and execute it in the browser. The executable payload is not present for static inspection or integrity verification.
Package source references dynamic require/import behavior.
dist/detectorLoader.jsView on unpkg · L4Package metadata claims a different repository identity while copied source loads a runtime dependency bridge.
dist/cjs/customDetectBot.cjsView on unpkg · L3A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
src/customDetectBot.ts#virtual:normalized:round1View on unpkgIt dynamically imports executable JavaScript supplied as a provider detector bundle.
src/detectorLoader.tsView on unpkg · L67The package deliberately accepts obfuscated per-session detector code, leaving its runtime behavior outside this package snapshot.
src/customDetectBot.tsView on unpkg · L303This report applies to @prosopo/procaptcha-frictionless@2.15.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Package source references dynamic require/import behavior.
dist/detectorLoader.jsView on unpkg · L4A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
src/customDetectBot.ts#virtual:normalized:round1View on unpkgPackage metadata claims a different repository identity while copied source loads a runtime dependency bridge.
dist/cjs/customDetectBot.cjsView on unpkg · L3It dynamically imports executable JavaScript supplied as a provider detector bundle.
src/detectorLoader.tsView on unpkg · L67The package deliberately accepts obfuscated per-session detector code, leaving its runtime behavior outside this package snapshot.
src/customDetectBot.tsView on unpkg · L303