PkgRadar

Composer · packagist.org

tina4stack/tina4php

Php Base64 Eval Chain: base64/gz/hex decode combined with eval/exec/backticks — classic PHP obfuscated payload.

Why PkgRadar flagged 3.13.13

SeveritySignalEvidence
highPhp Base64 Eval Chainbase64/gz/hex decode combined with eval/exec/backticks — classic PHP obfuscated payload. · tina4stack-tina4-php-a14f825/Tina4/Auth.php
highPhp Base64 Eval Chainbase64/gz/hex decode combined with eval/exec/backticks — classic PHP obfuscated payload. · tina4stack-tina4-php-a14f825/Tina4/Frond.php
highPhp Base64 Eval Chainbase64/gz/hex decode combined with eval/exec/backticks — classic PHP obfuscated payload. · tina4stack-tina4-php-a14f825/Tina4/MCP.php
highPhp Remote Fetch Exec ComboRemote fetch (file_get_contents/curl) paired with eval/exec — fetch-and-run pattern. · tina4stack-tina4-php-a14f825/Tina4/DevAdmin.php
highPhp Backtick With DecodeBacktick shell-out combined with base64/hex decode. · tina4stack-tina4-php-a14f825/Tina4/Auth.php
highPhp Backtick With DecodeBacktick shell-out combined with base64/hex decode. · tina4stack-tina4-php-a14f825/Tina4/Frond.php
highPhp Shell With Decodeexec / system / shell_exec combined with base64/hex decode. · tina4stack-tina4-php-a14f825/Tina4/MCP.php

Scanned versions

VersionVerdictScoreScanned (UTC)
3.13.13Review492026-06-11
3.13.9Review492026-06-10
3.13.7Review492026-06-10
3.13.5Review492026-06-05
3.13.4Review432026-06-04
3.13.2Review432026-06-03
3.13.0Review432026-06-01
3.12.14Review332026-05-31

Block this in CI

PkgRadar gates tina4stack/tina4php (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem composer tina4stack/[email protected]