Loading npm security reports…
Loading the published main module in a browser reads document.cookie and posts it to webhook.site. There is no feed-widget logic; the only runtime behavior is cookie theft.
index.js runs as soon as the module loads and sends document.cookie to an unrelated webhook.site URL.
index.jsView on unpkg · L1package.json points main at index.js and has no widget-helper code, only an empty description.
package.jsonView on unpkg · L1This report applies to feed-widget-helper@1.0.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
index.js runs as soon as the module loads and sends document.cookie to an unrelated webhook.site URL.
index.jsView on unpkg · L1package.json points main at index.js and has no widget-helper code, only an empty description.
package.jsonView on unpkg · L1