PkgRadar

Composer · packagist.org

zealphp/zealphp

Php Base64 Eval Chain: base64/gz/hex decode combined with eval/exec/backticks — classic PHP obfuscated payload.

Why PkgRadar flagged v0.4.8

SeveritySignalEvidence
highPhp Base64 Eval Chainbase64/gz/hex decode combined with eval/exec/backticks — classic PHP obfuscated payload. · sibidharan-zealphp-f323250/src/App.php
highPhp Base64 Eval Chainbase64/gz/hex decode combined with eval/exec/backticks — classic PHP obfuscated payload. · sibidharan-zealphp-f323250/src/CGI/WorkerPool.php
highPhp Base64 Eval Chainbase64/gz/hex decode combined with eval/exec/backticks — classic PHP obfuscated payload. · sibidharan-zealphp-f323250/src/Middleware/BasicAuthMiddleware.php
highPhp Base64 Eval Chainbase64/gz/hex decode combined with eval/exec/backticks — classic PHP obfuscated payload. · sibidharan-zealphp-f323250/src/fork_master.php
highPhp Base64 Eval Chainbase64/gz/hex decode combined with eval/exec/backticks — classic PHP obfuscated payload. · sibidharan-zealphp-f323250/src/pool_worker.php
highPhp Base64 Eval Chainbase64/gz/hex decode combined with eval/exec/backticks — classic PHP obfuscated payload. · sibidharan-zealphp-f323250/tests/Unit/CompressionMiddlewareTest.php
highPhp Base64 Eval Chainbase64/gz/hex decode combined with eval/exec/backticks — classic PHP obfuscated payload. · sibidharan-zealphp-f323250/tests/Unit/Middleware/CompressionExtraTest.php
highPhp Remote Fetch Exec ComboRemote fetch (file_get_contents/curl) paired with eval/exec — fetch-and-run pattern. · sibidharan-zealphp-f323250/src/utils.php
highPhp Remote Fetch Exec ComboRemote fetch (file_get_contents/curl) paired with eval/exec — fetch-and-run pattern. · sibidharan-zealphp-f323250/tests/Integration/CoroutineIsolationContractTest.php
highPhp Remote Fetch Exec ComboRemote fetch (file_get_contents/curl) paired with eval/exec — fetch-and-run pattern. · sibidharan-zealphp-f323250/tests/Integration/CoroutineLegacyBehaviorTest.php
highPhp Remote Fetch Exec ComboRemote fetch (file_get_contents/curl) paired with eval/exec — fetch-and-run pattern. · sibidharan-zealphp-f323250/tests/Integration/PhpInputIsolationTest.php
highPhp Remote Fetch Exec ComboRemote fetch (file_get_contents/curl) paired with eval/exec — fetch-and-run pattern. · sibidharan-zealphp-f323250/tests/Integration/TrustBarIsolationTest.php

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.4.8High risk1862026-06-10
v0.4.6High risk1862026-06-10

Block this in CI

PkgRadar gates zealphp/zealphp (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem composer zealphp/[email protected]