PkgRadar

Composer · packagist.org

useburrow/sdk-php

Remote Payload: matched "cURL "

Why PkgRadar flagged 0.9.8

SeveritySignalEvidence
mediumRemote Payloadmatched "cURL " · useburrow-sdk-php-ef31881/src/Transport/CurlHttpTransport.php

Scanned versions

VersionVerdictScoreScanned (UTC)
0.9.8Review122026-06-15

Block this in CI

PkgRadar gates useburrow/sdk-php (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem composer useburrow/[email protected]