PkgRadar

Composer · packagist.org

godaddy/asherah

Remote Payload: matched "github.com/godaddy/asherah-ffi/releases/download"

Why PkgRadar flagged v0.6.113

SeveritySignalEvidence
mediumRemote Payloadmatched "github.com/godaddy/asherah-ffi/releases/download" · godaddy-asherah-ffi-56fdc50/asherah-php/src/NativeLibraryInstaller.php

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.6.113Review122026-06-10
v0.6.112Review122026-06-09
v0.6.110Review122026-06-05
v0.6.108Review122026-06-03

Block this in CI

PkgRadar gates godaddy/asherah (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem composer godaddy/[email protected]
godaddy/asherah — Composer security scan | PkgRadar