PkgRadar

Composer · packagist.org

wpovernight/woocommerce-pdf-invoices-packing-slips

Php Base64 Eval Chain: base64/gz/hex decode combined with eval/exec/backticks — classic PHP obfuscated payload.

Why PkgRadar flagged v5.14.0

SeveritySignalEvidence
highPhp Base64 Eval Chainbase64/gz/hex decode combined with eval/exec/backticks — classic PHP obfuscated payload. · wpovernight-woocommerce-pdf-invoices-packing-slips-11a80c3/vendor/strauss/dompdf/dompdf/src/Helpers.php
highPhp Backtick With DecodeBacktick shell-out combined with base64/hex decode. · wpovernight-woocommerce-pdf-invoices-packing-slips-11a80c3/vendor/strauss/dompdf/dompdf/src/Helpers.php

Scanned versions

VersionVerdictScoreScanned (UTC)
v5.14.0Review222026-06-08

Block this in CI

PkgRadar gates wpovernight/woocommerce-pdf-invoices-packing-slips (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem composer wpovernight/[email protected]