Composer · packagist.org
jolicode/castor
Remote Payload: matched "github.com/crazywhalecc/static-php-cli/releases/download"
Why PkgRadar flagged v1.5.0
| Severity | Signal | Evidence |
|---|---|---|
| medium | Remote Payload | matched "github.com/crazywhalecc/static-php-cli/releases/download" · jolicode-castor-6fb32aa/src/Console/Command/CompileCommand.php |
| medium | Remote Payload | matched "curl " · jolicode-castor-6fb32aa/src/Listener/UpdateCastorListener.php |
| medium | Remote Payload | matched "raw.githubusercontent.com" · jolicode-castor-6fb32aa/tools/mkdocs/castor.php |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
v1.5.0 | Review | 23 | 2026-05-27 |
Block this in CI
pkgradar gate --ecosystem composer jolicode/[email protected]