PkgRadar

Composer · packagist.org

o3-shop/shop-ce

Php Remote Include: include/require pulls code from an http(s) URL — remote code injection primitive.

Why PkgRadar flagged v1.6.1-RC9

SeveritySignalEvidence
highPhp Remote Includeinclude/require pulls code from an http(s) URL — remote code injection primitive. · o3-shop-shop-ce-f7ca3e9/tests/Unit/Internal/Transition/Adapter/TemplateLogic/ScriptLogicTest.php
mediumRemote Payloadmatched "cUrl " · o3-shop-shop-ce-f7ca3e9/source/Application/Controller/Admin/ShopSeo.php
mediumRemote Payloadmatched "cUrl " · o3-shop-shop-ce-f7ca3e9/source/Application/Model/Article.php
mediumRemote Payloadmatched "cURL " · o3-shop-shop-ce-f7ca3e9/source/Application/translations/de/lang.php
mediumRemote Payloadmatched "cURL " · o3-shop-shop-ce-f7ca3e9/source/Application/translations/en/lang.php
mediumRemote Payloadmatched "cURL " · o3-shop-shop-ce-f7ca3e9/source/Application/views/admin/de/lang.php
mediumRemote Payloadmatched "cURL " · o3-shop-shop-ce-f7ca3e9/source/Application/views/admin/en/lang.php
mediumRemote Payloadmatched "cUrl " · o3-shop-shop-ce-f7ca3e9/source/Core/Smarty/Plugin/function.oxgetseourl.php
mediumRemote Payloadmatched "curl " · o3-shop-shop-ce-f7ca3e9/source/Internal/Framework/UpdateCheck/UpdateCheckService.php
mediumRemote Payloadmatched "cUrl " · o3-shop-shop-ce-f7ca3e9/source/Internal/Transition/Adapter/TemplateLogic/SeoUrlLogic.php
mediumRemote Payloadmatched "curl " · o3-shop-shop-ce-f7ca3e9/tests/Integration/Core/DynImgGeneratorTest.php
mediumRemote Payloadmatched "curl " · o3-shop-shop-ce-f7ca3e9/tests/Integration/OnlineInfo/OnlineLicenseCheckRequestFormationTest.php

Scanned versions

VersionVerdictScoreScanned (UTC)
v1.6.1-RC9High risk752026-05-30

Block this in CI

PkgRadar gates o3-shop/shop-ce (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem composer o3-shop/[email protected]