PkgRadar

Composer · packagist.org

joepdooper/ivy

Remote Payload: matched "curl "

Why PkgRadar flagged v0.9.14-alpha

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · joepdooper-ivy-caed4b6/plugins/bandsintown/classes/Settings.php
mediumRemote Payloadmatched "curl " · joepdooper-ivy-caed4b6/plugins/moments/collection/momentlocation/classes/MomentLocationHelper.php
mediumRemote Payloadmatched "Curl " · joepdooper-ivy-caed4b6/plugins/nextcloudapi/classes/NextcloudApiClient.php
mediumRemote Payloadmatched "curl " · joepdooper-ivy-caed4b6/plugins/tasmota/classes/Settings.php

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.9.14-alphaHigh risk482026-05-31

Block this in CI

PkgRadar gates joepdooper/ivy (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem composer joepdooper/[email protected]