PkgRadar

Composer · packagist.org

humanmade/local-server

Credential file access: matched "AWS_ACCESS_KEY"

Why PkgRadar flagged 26.0.10

SeveritySignalEvidence
highCredential file accessmatched "AWS_ACCESS_KEY" · humanmade-altis-local-server-fa8a4fd/inc/composer/class-command.php
mediumComposer Abandoned PackagePackagist marked this package abandoned — maintainer signaled it should not be used.
mediumRemote Payloadmatched "github.com/FiloSottile/mkcert/releases/download" · humanmade-altis-local-server-fa8a4fd/inc/composer/class-command.php

Scanned versions

VersionVerdictScoreScanned (UTC)
26.0.10Review182026-06-05
25.0.13Review52026-06-05

Block this in CI

PkgRadar gates humanmade/local-server (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem composer humanmade/[email protected]