PkgRadar

Composer · packagist.org

kantorge/yaffa

Remote Payload: matched "curl "

Why PkgRadar flagged 3.4.0

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · kantorge-yaffa-503cbea/app/Services/ProcessingHistoryRecorder.php
mediumRemote Payloadmatched "cURL " · kantorge-yaffa-503cbea/tests/Unit/Services/AiStepGatewayTest.php
mediumRemote Payloadmatched "cURL " · kantorge-yaffa-503cbea/tests/Unit/Services/ProcessDocumentServiceTest.php
mediumRemote Payloadmatched "cURL " · kantorge-yaffa-503cbea/tests/Unit/Services/ProcessingHistoryRecorderTest.php

Scanned versions

VersionVerdictScoreScanned (UTC)
3.4.0High risk292026-06-17
3.3.0High risk292026-06-11
3.2.0High risk292026-05-31

Block this in CI

PkgRadar gates kantorge/yaffa (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem composer kantorge/[email protected]