PkgRadar

Composer · packagist.org

ceus-media/hymn

Php Remote Fetch Exec Combo: Remote fetch (file_get_contents/curl) paired with eval/exec — fetch-and-run pattern.

Why PkgRadar flagged 1.0.4

SeveritySignalEvidence
highPhp Remote Fetch Exec ComboRemote fetch (file_get_contents/curl) paired with eval/exec — fetch-and-run pattern. · CeusMedia-Hymn-4b87ccb/build/create.php

Scanned versions

VersionVerdictScoreScanned (UTC)
1.0.4High risk172026-05-30

Related campaigns

Block this in CI

PkgRadar gates ceus-media/hymn (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem composer ceus-media/[email protected]