
Research
/Security News
TensorLake npm SDK Compromised in ChainDrop Shai-Hulud Credential-Stealing Attack
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.
@usefillo/dom
Advanced tools
Framework-agnostic DOM renderer and web component for embedding Fillo forms.
Docs · Guides · Examples · Changelog
Framework-agnostic DOM renderer, web component, and standalone browser bundle for Fillo — forms that render inside your own product, no iframe. Use it with Vue, Svelte, Astro, or plain browser JavaScript.
npm i @usefillo/dom
import { renderForm } from "@usefillo/dom";
import "@usefillo/dom/styles.css"; // optional default theme — or bring your own
renderForm("#fillo-form", {
formId: "cust-feedback",
onSubmitted: (id) => console.log("response", id),
});
Published formId embeds can fetch and submit without a publishable key. Use createClient({ key }) only when syncing code-defined schemas, or when you need to point the SDK at a custom API origin.
import { createClient, defineForm, renderForm } from "@usefillo/dom";
const client = createClient({ key: "pk_…" }); // Settings → Code-defined forms
const form = defineForm({
id: "cust-feedback",
pages: [{ id: "p1", blocks: [
{ id: "email", kind: "email", label: "Work email", required: true },
{ id: "msg", kind: "long_text", label: "What should we know?" },
] }],
});
renderForm("#fillo-form", {
form,
client,
onSubmitted: (id) => console.log("response", id),
});
Or drop it in with a single script tag — the bundle exposes a global Fillo:
<div id="fillo-form"></div>
<script src="https://unpkg.com/@usefillo/dom/dist/standalone.global.js"></script>
<script>
const client = Fillo.createClient({ key: "pk_…" });
const form = Fillo.defineForm({ id: "cust-feedback", pages: [/* … */] });
Fillo.renderForm("#fillo-form", { form, client });
</script>
The default stylesheet inherits the host page's CSS color-scheme and font. If your theme switch only toggles a class or data attribute, pass its resolved mode as theme: { colorScheme: "light" | "dark" }. Use "auto" only for a deliberately system-driven page. A fixed hex background automatically selects a readable palette unless you explicitly choose one.
Every rendered part carries data-* state attributes (data-selected, data-invalid, …) for utility CSS, and the default stylesheet is cascade-layered so your own styles win. On Tailwind v3 or reset-heavy sites import @usefillo/dom/styles.unlayered.css instead. Styling contract: fillo.so/docs/styling.
MIT licensed.
FAQs
Framework-agnostic DOM renderer and web component for embedding Fillo forms.
The npm package @usefillo/dom receives a total of 601 weekly downloads. As such, @usefillo/dom popularity was classified as not popular.
We found that @usefillo/dom demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.

Research
/Security News
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.