PkgRadar

Composer · packagist.org

it-healer/laravel-telegram-bot

Remote Payload: matched "curl "

Why PkgRadar flagged v1.3.0

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · it-healer-laravel-telegram-bot-e68bd7b/src/Controllers/WebhookController.php
mediumRemote Payloadmatched "curl " · it-healer-laravel-telegram-bot-e68bd7b/src/Services/LiveRunService.php
mediumRemote Payloadmatched "curl " · it-healer-laravel-telegram-bot-e68bd7b/src/Services/PollingService.php

Scanned versions

VersionVerdictScoreScanned (UTC)
v1.3.0High risk282026-06-17
v1.1.0High risk282026-06-17

Block this in CI

PkgRadar gates it-healer/laravel-telegram-bot (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem composer it-healer/[email protected]