PkgRadar

Composer · packagist.org

alexamiryan/stingle

Php Base64 Eval Chain, Php Shell With Decode, Remote Payload

Why PkgRadar flagged 3.4.11

SeveritySignalEvidence
highPhp Base64 Eval Chainalexamiryan-stingle-1e69d2d/packages/Mail/PHPMailTransport/PHPMailer/PHPMailer.php
highPhp Shell With Decodealexamiryan-stingle-1e69d2d/packages/Mail/PHPMailTransport/PHPMailer/PHPMailer.php
mediumRemote Payloadalexamiryan-stingle-1e69d2d/packages/Output/Minify/lib/Minify/JS/ClosureCompiler.php

Showing signal labels only. Sign in to view the exact matched indicators for each finding.

Scanned versions

VersionVerdictScoreScanned (UTC)
3.4.11High risk432026-06-21

Related campaigns

Block this in CI

PkgRadar gates alexamiryan/stingle (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem composer alexamiryan/[email protected]