PkgRadar

Composer · packagist.org

emaia/laravel-mediaman

Php Base64 Eval Chain, Php Shell With Decode

Why PkgRadar flagged v3.0.0

SeveritySignalEvidence
highPhp Base64 Eval Chainemaia-laravel-mediaman-668fc1b/tests/Feature/MultiSourceUploadTest.php
highPhp Shell With Decodeemaia-laravel-mediaman-668fc1b/tests/Feature/MultiSourceUploadTest.php

Showing signal labels only. Sign in to view the exact matched indicators for each finding.

Scanned versions

VersionVerdictScoreScanned (UTC)
v3.0.0High risk752026-06-26
v2.18.0Low risk02026-06-20
v2.17.2Low risk02026-06-20
v2.17.1Low risk02026-06-20
v2.16.0Low risk02026-06-19
v2.15.0Low risk02026-06-18
v2.13.0Low risk02026-06-18
v2.14.0Low risk02026-06-18
v2.12.0Low risk02026-06-18
v2.11.0Low risk02026-06-17
v2.7.0Low risk02026-06-17
v2.6.0Low risk02026-06-16
v2.4.0Low risk02026-06-16
v2.3.0Low risk02026-06-16

Block this in CI

PkgRadar gates emaia/laravel-mediaman (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem composer emaia/[email protected]