PkgRadar

Composer · packagist.org

therealworld/clirun-plugin

Php Base64 Eval Chain: base64/gz/hex decode combined with eval/exec/backticks — classic PHP obfuscated payload.

Why PkgRadar flagged v4.0.24

SeveritySignalEvidence
highPhp Base64 Eval Chainbase64/gz/hex decode combined with eval/exec/backticks — classic PHP obfuscated payload. · therealworld-clirun-plugin-1b16bc8b04f4/src/Command/DecodeLegacyCommand.php
highPhp Shell With Decodeexec / system / shell_exec combined with base64/hex decode. · therealworld-clirun-plugin-1b16bc8b04f4/src/Command/DecodeLegacyCommand.php

Scanned versions

VersionVerdictScoreScanned (UTC)
v4.0.24High risk372026-06-08
4.0.23High risk372026-06-02

Block this in CI

PkgRadar gates therealworld/clirun-plugin (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem composer therealworld/[email protected]