PkgRadar

Composer · packagist.org

soderlind/vmfa

Remote Payload: matched "raw.githubusercontent.com"

Why PkgRadar flagged 1.5.4

SeveritySignalEvidence
mediumRemote Payloadmatched "raw.githubusercontent.com" · soderlind-vmfa-080e0f2/src/AddonCatalog.php
mediumRemote Payloadmatched "raw.githubusercontent.com" · soderlind-vmfa-080e0f2/tests/unit/AddonCatalogTest.php

Scanned versions

VersionVerdictScoreScanned (UTC)
1.5.4Review242026-06-16

Block this in CI

PkgRadar gates soderlind/vmfa (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem composer soderlind/[email protected]