PkgRadar

Composer · packagist.org

bboezio/neophp

Remote Payload: matched "cURL "

Why PkgRadar flagged v2.19.2

SeveritySignalEvidence
mediumRemote Payloadmatched "cURL " · BenjiLeLoustik-NeoPHP-d3c0a8e/neo/Core/Console/Commands/MakeDeploymentCommand.php

Scanned versions

VersionVerdictScoreScanned (UTC)
v2.19.2Review122026-06-13
v2.19.0Review122026-06-08
v2.17.0Review122026-06-07
v2.16.0Review122026-06-07
v2.15.0Review122026-06-07
v2.12.0Review122026-06-06
v2.13.0Review122026-06-06
v2.11.0Review122026-06-06
v2.10.0Review122026-06-06
v2.7.0Review122026-05-31
v2.3.0Review122026-05-30
v2.4.0Review122026-05-30
v2.1.0Review122026-05-30
v2.1.1Review122026-05-30
v2.2.0Review122026-05-30
v2.0.0Review122026-05-30
v2.0.1Review122026-05-30
v1.17.0Review122026-05-30
v1.16.0Review122026-05-27
v1.15.0Review122026-05-27

Block this in CI

PkgRadar gates bboezio/neophp (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem composer bboezio/[email protected]