PkgRadar

Composer · packagist.org

averay/twig-extensions

Php Assert String Exec: assert() called with a variable — PHP's deprecated string-exec backdoor.

Why PkgRadar flagged 0.3.0

SeveritySignalEvidence
highPhp Assert String Execassert() called with a variable — PHP's deprecated string-exec backdoor. · adamaveray-twig-extensions-4777091/src/Nodes/AssertNode.php

Scanned versions

VersionVerdictScoreScanned (UTC)
0.3.0High risk282026-05-30

Related campaigns

Block this in CI

PkgRadar gates averay/twig-extensions (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem composer averay/[email protected]