PkgRadar

Composer · packagist.org

baige/monthpay

Remote Payload: matched "curl "

Why PkgRadar flagged v1.1.8

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · chenms66-monthpay-59c0547/src/Gateways/V1/BankGateway.php
mediumRemote Payloadmatched "curl " · chenms66-monthpay-59c0547/src/Gateways/V1/YeepayGateway.php
mediumRemote Payloadmatched "curl " · chenms66-monthpay-59c0547/src/Gateways/V2/YeepayGateway.php
mediumRemote Payloadmatched "curl " · chenms66-monthpay-59c0547/src/Support/HttpClient.php

Scanned versions

VersionVerdictScoreScanned (UTC)
v1.1.8High risk482026-06-16
v1.1.4High risk362026-06-12
v1.1.3Review242026-06-02
v1.1.2Review242026-05-29

Block this in CI

PkgRadar gates baige/monthpay (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem composer baige/[email protected]