PkgRadar

Composer · packagist.org

ec-europa/toolkit

Php Remote Fetch Exec Combo: Remote fetch (file_get_contents/curl) paired with eval/exec — fetch-and-run pattern.

Why PkgRadar flagged 10.28.0

SeveritySignalEvidence
highPhp Remote Fetch Exec ComboRemote fetch (file_get_contents/curl) paired with eval/exec — fetch-and-run pattern. · ec-europa-toolkit-8572f09/src/TaskRunner/Commands/DocumentationCommands.php
mediumRemote Payloadmatched "curl " · ec-europa-toolkit-8572f09/src/DrupalReleaseHistory.php
mediumRemote Payloadmatched "curl " · ec-europa-toolkit-8572f09/src/TaskRunner/Commands/BlackfireCommands.php

Scanned versions

VersionVerdictScoreScanned (UTC)
10.28.0Review192026-06-03

Block this in CI

PkgRadar gates ec-europa/toolkit (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem composer ec-europa/[email protected]