Composer · packagist.org
codego/php-ksip-telnet
Php Base64 Eval Chain: base64/gz/hex decode combined with eval/exec/backticks — classic PHP obfuscated payload.
Why PkgRadar flagged v4.0.4
| Severity | Signal | Evidence |
|---|---|---|
| high | Php Base64 Eval Chain | base64/gz/hex decode combined with eval/exec/backticks — classic PHP obfuscated payload. · kitenebie-FreePBX-Console-7560b1a/stubs/create_freepbx_extension_v17.php |
| high | Php Shell With Decode | exec / system / shell_exec combined with base64/hex decode. · kitenebie-FreePBX-Console-7560b1a/stubs/create_freepbx_extension_v17.php |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
v4.0.4 | High risk | 75 | 2026-06-17 |
v4.0.5 | High risk | 100 | 2026-06-17 |
v5.1.0 | High risk | 100 | 2026-06-17 |
v5.2.0 | High risk | 100 | 2026-06-17 |
v5.3.0 | High risk | 100 | 2026-06-17 |
v4.0.2 | High risk | 75 | 2026-06-17 |
Block this in CI
pkgradar gate --ecosystem composer codego/[email protected]