PkgRadar

Composer · packagist.org

pinoox/pincore

Php Base64 Eval Chain: base64/gz/hex decode combined with eval/exec/backticks — classic PHP obfuscated payload.

Why PkgRadar flagged 3.0.3

SeveritySignalEvidence
highPhp Base64 Eval Chainbase64/gz/hex decode combined with eval/exec/backticks — classic PHP obfuscated payload. · pinoox-pincore-cbad87c/Component/Package/Pinx/PinxSignKey.php
highPhp Shell With Decodeexec / system / shell_exec combined with base64/hex decode. · pinoox-pincore-cbad87c/Component/Package/Pinx/PinxSignKey.php
mediumRemote Payloadmatched "curl " · pinoox-pincore-cbad87c/Component/Kernel/Debug/Support/ExceptionContext.php
mediumRemote Payloadmatched "cURL " · pinoox-pincore-cbad87c/Component/Kernel/Debug/Support/ExceptionHintResolver.php
mediumRemote Payloadmatched "cURL " · pinoox-pincore-cbad87c/resource/debug/views/exception.html.php
mediumRemote Payloadmatched "cURL " · pinoox-pincore-cbad87c/resource/debug/views/exception_preview.html.php

Scanned versions

VersionVerdictScoreScanned (UTC)
3.0.3High risk1282026-06-11
3.0.2High risk1282026-06-11
3.0.1High risk1282026-06-11

Block this in CI

PkgRadar gates pinoox/pincore (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem composer pinoox/[email protected]