Composer · packagist.org
maikuolan/cidram
Php Base64 Eval Chain: base64/gz/hex decode combined with eval/exec/backticks — classic PHP obfuscated payload.
Why PkgRadar flagged v1.29.7
| Severity | Signal | Evidence |
|---|---|---|
| high | Php Base64 Eval Chain | base64/gz/hex decode combined with eval/exec/backticks — classic PHP obfuscated payload. · CIDRAM-CIDRAM-535b3e5/vault/classes/Maikuolan/Cache.php |
| high | Php Shell With Decode | exec / system / shell_exec combined with base64/hex decode. · CIDRAM-CIDRAM-535b3e5/vault/classes/Maikuolan/Cache.php |
| medium | Remote Payload | matched "raw.githubusercontent.com" · CIDRAM-CIDRAM-535b3e5/vault/frontend.php |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
v1.29.7 | Review | 26 | 2026-06-10 |
v2.17.4 | Review | 26 | 2026-06-10 |
v3.12.0 | Review | 27 | 2026-06-10 |
v4.2.0 | Review | 32 | 2026-06-10 |
Block this in CI
pkgradar gate --ecosystem composer maikuolan/[email protected]