PkgRadar

Composer · packagist.org

grandchef/dfe

Remote Payload: matched "Curl\n"

Why PkgRadar flagged 5.0.11

SeveritySignalEvidence
mediumRemote Payloadmatched "Curl\n" · grandchef-dfe-3035ea4/src/DFe/Common/CurlSoap.php
mediumRemote Payloadmatched "curl " · grandchef-dfe-3035ea4/src/DFe/Database/IBPT.php
mediumRemote Payloadmatched "curl " · grandchef-dfe-3035ea4/utils/atualiza_servicos.php

Scanned versions

VersionVerdictScoreScanned (UTC)
5.0.11High risk252026-06-08
5.0.10High risk252026-06-08

Block this in CI

PkgRadar gates grandchef/dfe (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem composer grandchef/[email protected]