PkgRadar

Composer · packagist.org

automattic/jetpack

Php Base64 Eval Chain: base64/gz/hex decode combined with eval/exec/backticks — classic PHP obfuscated payload.

Why PkgRadar flagged 15.9

SeveritySignalEvidence
highPhp Base64 Eval Chainbase64/gz/hex decode combined with eval/exec/backticks — classic PHP obfuscated payload. · Automattic-jetpack-production-ec68686/jetpack_vendor/automattic/jetpack-backup/src/class-rest-controller.php
highPhp Backtick With DecodeBacktick shell-out combined with base64/hex decode. · Automattic-jetpack-production-ec68686/jetpack_vendor/automattic/jetpack-backup/src/class-rest-controller.php
mediumRemote Payloadmatched "cURL " · Automattic-jetpack-production-ec68686/jetpack_vendor/automattic/jetpack-connection/src/health/class-connection-health-tests.php
mediumRemote Payloadmatched "curl " · Automattic-jetpack-production-ec68686/json-endpoints/class.wpcom-json-api-edit-media-v1-2-endpoint.php
mediumRemote Payloadmatched "curl " · Automattic-jetpack-production-ec68686/json-endpoints/class.wpcom-json-api-update-post-endpoint.php
mediumRemote Payloadmatched "curl " · Automattic-jetpack-production-ec68686/json-endpoints/class.wpcom-json-api-update-post-v1-1-endpoint.php
mediumRemote Payloadmatched "curl " · Automattic-jetpack-production-ec68686/json-endpoints/class.wpcom-json-api-update-post-v1-2-endpoint.php
mediumRemote Payloadmatched "curl " · Automattic-jetpack-production-ec68686/json-endpoints/class.wpcom-json-api-upload-media-endpoint.php
mediumRemote Payloadmatched "curl " · Automattic-jetpack-production-ec68686/json-endpoints/class.wpcom-json-api-upload-media-v1-1-endpoint.php

Scanned versions

VersionVerdictScoreScanned (UTC)
15.9Review412026-06-09

Block this in CI

PkgRadar gates automattic/jetpack (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem composer automattic/[email protected]