PkgRadar

Composer · packagist.org

rtcoder/devdoctor

Remote Payload: matched "github.com/rtcoder/devdoctor/releases/download"

Why PkgRadar flagged v1.48.0

SeveritySignalEvidence
mediumRemote Payloadmatched "github.com/rtcoder/devdoctor/releases/download" · rtcoder-devdoctor-69bb3fc/app/DevDoctor/Core/Updates/InstallationDetector.php
mediumRemote Payloadmatched "curl " · rtcoder-devdoctor-69bb3fc/tests/Unit/ComposerAnalyzerTest.php
mediumRemote Payloadmatched "curl " · rtcoder-devdoctor-69bb3fc/tests/Unit/JavaAnalyzerTest.php
mediumRemote Payloadmatched "curl " · rtcoder-devdoctor-69bb3fc/tests/Unit/McpAnalyzerTest.php
mediumRemote Payloadmatched "curl " · rtcoder-devdoctor-69bb3fc/tests/Unit/NodeAnalyzerTest.php
mediumRemote Payloadmatched "curl " · rtcoder-devdoctor-69bb3fc/tests/Unit/SecurityAnalyzerTest.php
mediumRemote Payloadmatched "curl " · rtcoder-devdoctor-69bb3fc/tests/Unit/SymfonyAnalyzerTest.php

Scanned versions

VersionVerdictScoreScanned (UTC)
v1.48.0High risk672026-06-08
v1.43.0High risk672026-06-08
v1.45.0High risk672026-06-08
v1.44.0High risk672026-06-08
v1.41.0High risk672026-06-08
v1.39.0High risk672026-06-07
v1.38.2High risk672026-06-07
v1.38.1High risk672026-06-07
v1.40.0High risk672026-06-07
v1.36.0High risk552026-06-07

Block this in CI

PkgRadar gates rtcoder/devdoctor (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem composer rtcoder/[email protected]