PkgRadar

Composer · packagist.org

zxf/security

Php Remote Include: include/require pulls code from an http(s) URL — remote code injection primitive.

Why PkgRadar flagged v1.1.8

SeveritySignalEvidence
highPhp Remote Includeinclude/require pulls code from an http(s) URL — remote code injection primitive. · zhaoxianfang-security-b67483f/tests/_audit1.php
mediumRemote Payloadmatched "wget " · zhaoxianfang-security-b67483f/tests/_audit1.php
mediumRemote Payloadmatched "curl " · zhaoxianfang-security-b67483f/tests/_audit2.php
mediumRemote Payloadmatched "curl " · zhaoxianfang-security-b67483f/tests/_audit_comprehensive.php

Scanned versions

VersionVerdictScoreScanned (UTC)
v1.1.8High risk672026-06-15

Block this in CI

PkgRadar gates zxf/security (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem composer zxf/[email protected]