PkgRadar

Composer · packagist.org

flow-php/flow

Php Assert String Exec: assert() called with a variable — PHP's deprecated string-exec backdoor.

Why PkgRadar flagged 0.40.0

SeveritySignalEvidence
highPhp Assert String Execassert() called with a variable — PHP's deprecated string-exec backdoor. · flow-php-flow-8143d2a/web/landing/content/examples/topics/types/assertions/callable/code.php
highPhp Assert String Execassert() called with a variable — PHP's deprecated string-exec backdoor. · flow-php-flow-8143d2a/web/landing/content/examples/topics/types/assertions/constrained/code.php
highPhp Assert String Execassert() called with a variable — PHP's deprecated string-exec backdoor. · flow-php-flow-8143d2a/web/landing/content/examples/topics/types/assertions/optional/code.php
mediumRemote Payloadmatched "CURL " · flow-php-flow-8143d2a/src/bridge/phpunit/telemetry/src/Flow/Bridge/PHPUnit/Telemetry/Configuration.php
mediumRemote Payloadmatched "curl " · flow-php-flow-8143d2a/src/bridge/symfony/telemetry-bundle/src/Flow/Bridge/Symfony/TelemetryBundle/FlowTelemetryBundle.php
mediumRemote Payloadmatched "curl " · flow-php-flow-8143d2a/src/bridge/telemetry/otlp/src/Flow/Bridge/Telemetry/OTLP/Transport/CurlTransport.php
mediumRemote Payloadmatched "curl " · flow-php-flow-8143d2a/src/lib/parquet-viewer/bin/parquet.php

Scanned versions

VersionVerdictScoreScanned (UTC)
0.40.0High risk512026-06-16

Block this in CI

PkgRadar gates flow-php/flow (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem composer flow-php/[email protected]