PkgRadar

Composer · packagist.org

sindla/aurora

Php Base64 Eval Chain: base64/gz/hex decode combined with eval/exec/backticks — classic PHP obfuscated payload.

Why PkgRadar flagged v8.1.3

SeveritySignalEvidence
highPhp Base64 Eval Chainbase64/gz/hex decode combined with eval/exec/backticks — classic PHP obfuscated payload. · SindlaXYZ-Aurora-89d6f61/src/Utils/AuroraPWA/AuroraPWA.php

Scanned versions

VersionVerdictScoreScanned (UTC)
v8.1.3Review132026-06-04
v8.1.2Review132026-05-30
v8.1.1Review132026-05-30
v8.1.0Review132026-05-29

Block this in CI

PkgRadar gates sindla/aurora (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem composer sindla/[email protected]