PkgRadar

Composer · packagist.org

sirosoft/core

Php Base64 Eval Chain: base64/gz/hex decode combined with eval/exec/backticks — classic PHP obfuscated payload.

Why PkgRadar flagged v0.35.0

SeveritySignalEvidence
highPhp Base64 Eval Chainbase64/gz/hex decode combined with eval/exec/backticks — classic PHP obfuscated payload. · SiroSoft-siro-core-bc83390/tests/security/PenetrationTest.php
mediumRemote Payloadmatched "curl " · SiroSoft-siro-core-bc83390/Commands/LogExportCommand.php
mediumRemote Payloadmatched "curl " · SiroSoft-siro-core-bc83390/Commands/LogReplayCommand.php
mediumRemote Payloadmatched "curl " · SiroSoft-siro-core-bc83390/Commands/MakeApiKeyCommand.php
mediumRemote Payloadmatched "curl " · SiroSoft-siro-core-bc83390/Commands/ServeCommand.php
mediumRemote Payloadmatched "curl " · SiroSoft-siro-core-bc83390/Http.php

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.35.0High risk1102026-06-07
v0.34.0High risk1102026-06-04
v0.33.1High risk1102026-06-02
v0.33.0High risk1102026-06-01
v0.32.1High risk1102026-05-31

Block this in CI

PkgRadar gates sirosoft/core (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem composer sirosoft/[email protected]