At widget runtime, the package downloads a detector script from a dynamically selected provider and executes it in the embedding page. This creates a provider-side supply-chain code-execution surface.
Package source references dynamic require/import behavior.
dist/detectorLoader.jsView on unpkg · L12Package metadata claims a different repository identity while copied source loads a runtime dependency bridge.
dist/cjs/AuthenticatedBadge.cjsView on unpkg · L1A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
src/customDetectBot.ts#virtual:normalized:round1View on unpkgThe widget requests a per-session detector script from a selected provider and passes it to a loader.
src/customDetectBot.tsView on unpkg · L225The loader turns supplied text into blob or data JavaScript and dynamically imports it, executing provider-controlled code in the host page.
src/detectorLoader.tsView on unpkg · L67This report applies to @prosopo/procaptcha-frictionless@2.16.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Package source references dynamic require/import behavior.
dist/detectorLoader.jsView on unpkg · L12Package metadata claims a different repository identity while copied source loads a runtime dependency bridge.
dist/cjs/AuthenticatedBadge.cjsView on unpkg · L1A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
src/customDetectBot.ts#virtual:normalized:round1View on unpkgThe widget requests a per-session detector script from a selected provider and passes it to a loader.
src/customDetectBot.tsView on unpkg · L225The loader turns supplied text into blob or data JavaScript and dynamically imports it, executing provider-controlled code in the host page.
src/detectorLoader.tsView on unpkg · L67