The package exposes a tiny entrypoint containing a webhook image-beacon payload. No confirmed outbound request occurs because the assignment uses an undeclared variable.
package.json exposes script.js as the package main entrypoint.
package.jsonView on unpkg · L5There are no npm lifecycle scripts or dependencies declared in package.json.
package.jsonView on unpkg · L5The entrypoint contains an external webhook URL labelled XSS_works, intended as an image request target.
script.jsView on unpkg · L2This report applies to npmscript_tesstalert_unpkg@1.1.2.
See version security history for other recorded verdicts.
Evidence last updated: .
package.json exposes script.js as the package main entrypoint.
package.jsonView on unpkg · L5There are no npm lifecycle scripts or dependencies declared in package.json.
package.jsonView on unpkg · L5The entrypoint contains an external webhook URL labelled XSS_works, intended as an image request target.
script.jsView on unpkg · L2