PkgRadar

Composer · packagist.org

dniccum/secret-stash-cli

Composer Install Scripts Present: composer.json declares pre/post install/update scripts — execute on composer install.

Scanned versions

VersionVerdictScoreScanned (UTC)
v1.0.2Review52026-06-16

Block this in CI

PkgRadar gates dniccum/secret-stash-cli (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem composer dniccum/[email protected]