PkgRadar

Composer · packagist.org

linhecheng/cmlphp

Php Remote Fetch Exec Combo: Remote fetch (file_get_contents/curl) paired with eval/exec — fetch-and-run pattern.

Why PkgRadar flagged v8.1.0

SeveritySignalEvidence
highPhp Remote Fetch Exec ComboRemote fetch (file_get_contents/curl) paired with eval/exec — fetch-and-run pattern. · symfony-symfony-0989c36/.github/build-packages.php
mediumComposer Abandoned PackagePackagist marked this package abandoned — maintainer signaled it should not be used.
mediumRemote Payloadmatched "cUrl " · symfony-symfony-0989c36/src/Symfony/Bundle/FrameworkBundle/Command/ConfigDebugCommand.php
mediumRemote Payloadmatched "cUrl " · symfony-symfony-0989c36/src/Symfony/Bundle/FrameworkBundle/Command/ConfigDumpReferenceCommand.php
mediumRemote Payloadmatched "cURL " · symfony-symfony-0989c36/src/Symfony/Bundle/FrameworkBundle/DependencyInjection/Configuration.php
mediumRemote Payloadmatched "iwr " · symfony-symfony-0989c36/src/Symfony/Component/Emoji/Resources/data/emoji-cy.php
mediumRemote Payloadmatched "curl " · symfony-symfony-0989c36/src/Symfony/Component/HttpClient/DataCollector/HttpClientDataCollector.php
mediumRemote Payloadmatched "curl " · symfony-symfony-0989c36/src/Symfony/Component/HttpClient/NativeHttpClient.php
mediumRemote Payloadmatched "curl " · symfony-symfony-0989c36/src/Symfony/Component/HttpClient/Response/CurlResponse.php

Scanned versions

VersionVerdictScoreScanned (UTC)
v8.1.0Review402026-05-29
v5.4.53Review542026-05-27
v6.4.41Review622026-05-27

Block this in CI

PkgRadar gates linhecheng/cmlphp (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem composer linhecheng/[email protected]