PkgRadar

Composer · packagist.org

yunzhanghuopen/sdk-php

Remote Payload: matched "curl "

Why PkgRadar flagged 2.0.29

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · YunzhanghuOpen-sdk-php-bc424da/src/BaseClient.php

Scanned versions

VersionVerdictScoreScanned (UTC)
2.0.29Review62026-06-03

Block this in CI

PkgRadar gates yunzhanghuopen/sdk-php (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem composer yunzhanghuopen/[email protected]