malware
The entire product is delivered as fetch(...).then(eval) you paste one line into your browser console, and their server gets to run arbitrary JavaScript on wplace.live under your own session. There is no version pinning, no hash, and no source repository, so whatever they serve today can silently become something else tomorrow, and a script with that access can read your session token. Even setting trust aside, wplace.live bans automation, so you're risking your account either way. Hard pass.
