PkgRadar

Composer · packagist.org

codesignificant/api-pro

Remote Payload: matched "Curl "

Why PkgRadar flagged v2.1.2

SeveritySignalEvidence
mediumRemote Payloadmatched "Curl " · CodeSignificant-api-pro-4d84cd1/Core/Security/TokenManager.php

Scanned versions

VersionVerdictScoreScanned (UTC)
v2.1.2Review172026-05-28
v2.0.0Review52026-05-27

Block this in CI

PkgRadar gates codesignificant/api-pro (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem composer codesignificant/[email protected]