PkgRadar

Composer · packagist.org

hypejunction/hypegeo

Remote Payload: matched "curl "

Why PkgRadar flagged 7.0.1

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · hypeJunction-hypeGeo-72da4f0/vendors/composer/installers/src/bootstrap.php
mediumRemote Payloadmatched "cURL " · hypeJunction-hypeGeo-72da4f0/vendors/willdurand/geocoder/src/Geocoder/HttpAdapter/CurlHttpAdapter.php
mediumRemote Payloadmatched "cURL " · hypeJunction-hypeGeo-72da4f0/vendors/willdurand/geocoder/tests/Geocoder/Tests/HttpAdapter/CurlHttpAdapterTest.php
mediumRemote Payloadmatched "cURL " · hypeJunction-hypeGeo-72da4f0/vendors/willdurand/geocoder/tests/bootstrap.php

Scanned versions

VersionVerdictScoreScanned (UTC)
7.0.1High risk482026-06-05

Block this in CI

PkgRadar gates hypejunction/hypegeo (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem composer hypejunction/[email protected]