PkgRadar

Composer · packagist.org

cesurapp/swoole-bundle

Remote Payload: matched "CURL "

Why PkgRadar flagged 1.2.13

SeveritySignalEvidence
mediumRemote Payloadmatched "CURL " · cesurapp-swoole-bundle-5bddd8d/src/Runtime/entrypoint.php

Scanned versions

VersionVerdictScoreScanned (UTC)
1.2.13Review62026-06-02

Block this in CI

PkgRadar gates cesurapp/swoole-bundle (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem composer cesurapp/[email protected]