Composer · packagist.org
mirandaleyva/contao-architecture_references
Php Base64 Eval Chain: base64/gz/hex decode combined with eval/exec/backticks — classic PHP obfuscated payload.
Why PkgRadar flagged v1.3.3
| Severity | Signal | Evidence |
|---|---|---|
| high | Php Base64 Eval Chain | base64/gz/hex decode combined with eval/exec/backticks — classic PHP obfuscated payload. · mirandaleyva-contao-architecture_references-13825b6/vendor/clue/stream-filter/src/functions.php |
| high | Php Base64 Eval Chain | base64/gz/hex decode combined with eval/exec/backticks — classic PHP obfuscated payload. · mirandaleyva-contao-architecture_references-13825b6/vendor/league/uri/Uri.php |
| high | Php Assert String Exec | assert() called with a variable — PHP's deprecated string-exec backdoor. · mirandaleyva-contao-architecture_references-13825b6/vendor/clue/stream-filter/src/functions.php |
| high | Php Backtick With Decode | Backtick shell-out combined with base64/hex decode. · mirandaleyva-contao-architecture_references-13825b6/vendor/league/uri/Uri.php |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
v1.3.3 | High risk | 120 | 2026-06-05 |
v1.3.4 | High risk | 120 | 2026-06-05 |
v1.3.2 | High risk | 120 | 2026-06-03 |
v1.2.3 | High risk | 120 | 2026-05-30 |
v1.2.4 | High risk | 120 | 2026-05-30 |
Block this in CI
pkgradar gate --ecosystem composer mirandaleyva/[email protected]