PkgRadar

Composer · packagist.org

kreuzberg-dev/html-to-markdown

Remote Payload: matched "curl "

Why PkgRadar flagged v3.6.0

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · kreuzberg-dev-html-to-markdown-fcd306e/e2e/php/tests/RealWorldTest.php

Scanned versions

VersionVerdictScoreScanned (UTC)
v3.6.0Review82026-06-12
v3.6.0-rc.24Review82026-06-12
v3.6.0-rc.22Review82026-06-08
v3.6.0-rc.21Review82026-06-07
v3.6.0-rc.20Review82026-06-07
v3.6.0-rc.19Review82026-06-07
v3.6.0-rc.17Review82026-06-06
v3.6.0-rc.16Review82026-06-06
v3.6.0-rc.14Review82026-06-05
v3.6.0-rc.11Review82026-06-04
v3.6.0-rc.10Review82026-06-04
v3.6.0-rc.9Review82026-06-04
v3.6.0-rc.7Review82026-06-03
v3.6.0-rc.5Review82026-06-02
v3.6.0-rc.2Review82026-06-02
v3.6.0-rc.1Review82026-06-01
v3.5.6Review82026-05-29
v3.5.4Review82026-05-28

Block this in CI

PkgRadar gates kreuzberg-dev/html-to-markdown (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem composer kreuzberg-dev/[email protected]