The published main file runs on import: it reads a flag-like value from /profile and POSTs it to /addPost. That is scrape-and-exfiltrate behavior, not a feed widget. There is no install-time hook.
index.js has no exports and immediately GET-fetches /profile when the module loads
index.jsView on unpkg · L1It parses a .flag-value node from that HTML and POSTs the text to /addPost
index.jsView on unpkg · L6The package is named a feed widget helper but has empty metadata and no widget API
package.jsonView on unpkg · L1This report applies to feed-widget-helper@1.0.4.
See version security history for other recorded verdicts.
Evidence last updated: .
index.js has no exports and immediately GET-fetches /profile when the module loads
index.jsView on unpkg · L1It parses a .flag-value node from that HTML and POSTs the text to /addPost
index.jsView on unpkg · L6The package is named a feed widget helper but has empty metadata and no widget API
package.jsonView on unpkg · L1