PkgRadar

Cargo · crates.io

x0x

Remote Payload: matched "github.com/saorsa-labs/x0x/releases/download"

Why PkgRadar flagged 0.24.0

SeveritySignalEvidence
mediumRemote Payloadmatched "github.com/saorsa-labs/x0x/releases/download" · x0x-0.24.0/src/bin/x0x-keygen.rs
mediumRemote Payloadmatched "curl " · x0x-0.24.0/src/bin/x0x.rs
mediumRemote Payloadmatched "curl " · x0x-0.24.0/src/cli/commands/upgrade.rs

Scanned versions

VersionVerdictScoreScanned (UTC)
0.24.0High risk362026-06-15
0.23.1High risk362026-06-11
0.23.0High risk362026-06-10
0.22.1High risk362026-06-10
0.22.0High risk362026-06-10
0.21.4High risk362026-06-10
0.21.3High risk362026-06-07
0.21.2High risk362026-06-05
0.21.1High risk362026-06-04
0.21.0High risk362026-06-03
0.20.2High risk362026-06-02
0.20.1High risk362026-06-02
0.20.0High risk362026-06-02
0.19.53Review362026-05-30
0.19.51High risk362026-05-30
0.19.50High risk362026-05-30
0.19.52Review362026-05-29

Block this in CI

PkgRadar gates x0x (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem cargo [email protected]