The browser widget fetches provider-controlled JavaScript text and executes it through dynamic module import. This gives the provider arbitrary code execution in every host page that mounts the default widget.
Package source references dynamic require/import behavior.
dist/detectorLoader.jsView on unpkg · L12Package metadata claims a different repository identity while copied source loads a runtime dependency bridge.
dist/cjs/AuthenticatedBadge.cjsView on unpkg · L1A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
src/customDetectBot.ts#virtual:normalized:round1View on unpkgThe imported provider code is invoked in the host page with the widget container and an account callback.
src/customDetectBot.tsView on unpkg · L304The loader turns supplied text into blob and data JavaScript URLs, then dynamically imports it.
src/detectorLoader.tsView on unpkg · L100This report applies to @prosopo/procaptcha-frictionless@2.16.2.
See version security history for other recorded verdicts.
Evidence last updated: .
Package source references dynamic require/import behavior.
dist/detectorLoader.jsView on unpkg · L12Package metadata claims a different repository identity while copied source loads a runtime dependency bridge.
dist/cjs/AuthenticatedBadge.cjsView on unpkg · L1A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
src/customDetectBot.ts#virtual:normalized:round1View on unpkgThe imported provider code is invoked in the host page with the widget container and an account callback.
src/customDetectBot.tsView on unpkg · L304The loader turns supplied text into blob and data JavaScript URLs, then dynamically imports it.
src/detectorLoader.tsView on unpkg · L100