PkgRadar

Composer · packagist.org

eav93/wreq-php

Remote Payload: matched "github.com/'.self::REPO.'/releases/download"

Why PkgRadar flagged v1.3.0

SeveritySignalEvidence
mediumRemote Payloadmatched "github.com/'.self::REPO.'/releases/download" · eav93-wreq-php-fbc6c2f/src-php/Installer.php

Scanned versions

VersionVerdictScoreScanned (UTC)
v1.3.0Review172026-05-28
v1.0.1Review172026-05-28
v1.0.2Review172026-05-28
v1.0.3Review172026-05-28
v1.0.4Review172026-05-28
v1.0.6Review172026-05-28
v1.0.0Review172026-05-27
v0.3.9Review172026-05-27
v0.3.8Review172026-05-27
v0.3.7Review172026-05-27

Block this in CI

PkgRadar gates eav93/wreq-php (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem composer eav93/[email protected]