PkgRadar

Composer · packagist.org

johnfmorton/craft-bespoken

Remote Payload: matched "curl "

Why PkgRadar flagged 5.3.4

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · johnfmorton-craft-bespoken-f116c42/src/controllers/BespokenController.php

Scanned versions

VersionVerdictScoreScanned (UTC)
5.3.4Review82026-06-12

Block this in CI

PkgRadar gates johnfmorton/craft-bespoken (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem composer johnfmorton/[email protected]