Packages scanned
4,408
Coverage composer
packagist.orgPHP. composer.json scripts run shell during install; PHP source carries the eval/exec primitives. Detection gates on combos: base64/gz/hex decode + eval/exec, remote include/require, deprecated assert(string) backdoor, and remote-fetch-with-exec chains.
4,408
148
987
404
39m ago
Install-time attack surface
scripts.{pre,post}-{install,update}-cmd in composer.json — run as shell commands during `composer install`
Supported lockfile formats
composer.lockSpec format
pkgradar gate --ecosystem composer symfony/[email protected]Recent activity
The corpus-wide release feed lives on /campaigns. A per-ecosystem release feed for Composer is on the roadmap — the stats above are filtered to this ecosystem in the meantime.
Other ecosystems