PkgRadar

Composer · packagist.org

grabzit/grabzit

Remote Payload: matched "CURL "

Why PkgRadar flagged 3.5.8

SeveritySignalEvidence
mediumRemote Payloadmatched "CURL " · GrabzIt-grabzit-php-f415abd/lib/GrabzItClient.php

Scanned versions

VersionVerdictScoreScanned (UTC)
3.5.8Review62026-06-18

Block this in CI

PkgRadar gates grabzit/grabzit (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem composer grabzit/[email protected]