PkgRadar

Composer · packagist.org

opencontent/openpa_bootstrapitalia-ls

Remote Payload: matched "cUrl "

Why PkgRadar flagged 2.39.5

SeveritySignalEvidence
mediumRemote Payloadmatched "cUrl " · OpencontentCoop-openpa_bootstrapitalia-e9c08c7/classes/bridge/SiteInfo.php
mediumRemote Payloadmatched "raw.githubusercontent.com" · OpencontentCoop-openpa_bootstrapitalia-e9c08c7/datatypes/openpacomuniitaliani/openpacomuniitaliani.php
mediumRemote Payloadmatched "Curl " · OpencontentCoop-openpa_bootstrapitalia-e9c08c7/eventtypes/event/remoteindex/RemoteIndexClient.php

Scanned versions

VersionVerdictScoreScanned (UTC)
2.39.5Review102026-06-16
2.39.6Review102026-06-16

Block this in CI

PkgRadar gates opencontent/openpa_bootstrapitalia-ls (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem composer opencontent/[email protected]