PkgRadar

Composer · packagist.org

diepxuan/laravel-catalog

Remote Payload: matched "raw.githubusercontent.com"

Why PkgRadar flagged 1.8.4

SeveritySignalEvidence
mediumRemote Payloadmatched "raw.githubusercontent.com" · diepxuan-laravel-catalog-149d938/.php-cs-fixer.dist.php
mediumRemote Payloadmatched "raw.githubusercontent.com" · diepxuan-laravel-catalog-149d938/resources/views/layouts/app.blade.php
mediumRemote Payloadmatched "raw.githubusercontent.com" · diepxuan-laravel-catalog-149d938/resources/views/layouts/master.blade.php

Scanned versions

VersionVerdictScoreScanned (UTC)
1.8.4High risk362026-06-09
1.8.3High risk362026-06-09
1.8.1High risk362026-06-06
1.7.9High risk362026-06-05
1.7.8High risk362026-06-05
1.7.7High risk362026-06-02

Block this in CI

PkgRadar gates diepxuan/laravel-catalog (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem composer diepxuan/[email protected]