PkgRadar

Composer · packagist.org

etechflow/module-in-store-pickup

Webhook Exfil Endpoint: matched "ngrok-free.app"

Why PkgRadar flagged 2.2.0

SeveritySignalEvidence
highWebhook Exfil Endpointmatched "ngrok-free.app" · etechflow-module-in-store-pickup-d80f075/Model/LicenseValidator.php
mediumRemote Payloadmatched "Curl " · etechflow-module-in-store-pickup-d80f075/Controller/Adminhtml/License/Activated.php
mediumRemote Payloadmatched "Curl " · etechflow-module-in-store-pickup-d80f075/Controller/Adminhtml/License/Checkout.php
mediumRemote Payloadmatched "Curl " · etechflow-module-in-store-pickup-d80f075/Model/Autofill/PostcodeLookupClient.php
mediumRemote Payloadmatched "Curl " · etechflow-module-in-store-pickup-d80f075/Model/LicenseValidator.php

Scanned versions

VersionVerdictScoreScanned (UTC)
2.2.0High risk882026-06-06
2.1.2High risk882026-06-04
1.3.2High risk522026-06-04
2.1.1High risk882026-06-03

Block this in CI

PkgRadar gates etechflow/module-in-store-pickup (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem composer etechflow/[email protected]