At captcha runtime, the package fetches an opaque detector script from a provider and executes it in the page. The provider and response-supplied beacon URLs are dynamic, so their hosts cannot be established from this snapshot.
Package source references dynamic require/import behavior.
dist/detectorLoader.jsView on unpkg · L12Package metadata claims a different repository identity while copied source loads a runtime dependency bridge.
dist/cjs/AuthenticatedBadge.cjsView on unpkg · L1A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
src/customDetectBot.ts#virtual:normalized:round1View on unpkgThe widget requests a per-session detector script from a dynamically selected provider.
src/customDetectBot.tsView on unpkg · L225It turns the received script into a blob or data URL and dynamically imports it, executing provider-controlled code.
src/detectorLoader.tsView on unpkg · L67This report applies to @prosopo/procaptcha-frictionless@2.16.1.
See version security history for other recorded verdicts.
Evidence last updated: .
Package source references dynamic require/import behavior.
dist/detectorLoader.jsView on unpkg · L12Package metadata claims a different repository identity while copied source loads a runtime dependency bridge.
dist/cjs/AuthenticatedBadge.cjsView on unpkg · L1A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
src/customDetectBot.ts#virtual:normalized:round1View on unpkgThe widget requests a per-session detector script from a dynamically selected provider.
src/customDetectBot.tsView on unpkg · L225It turns the received script into a blob or data URL and dynamically imports it, executing provider-controlled code.
src/detectorLoader.tsView on unpkg · L67