PkgRadar

Maven · repo1.maven.org

com.github.binarywang:weixin-java-mp

Remote Payload: matched "cUrl "

Why PkgRadar flagged 4.8.4-20260612.150047

SeveritySignalEvidence
mediumRemote Payloadmatched "cUrl " · me/chanjar/weixin/mp/bean/message/WxMpXmlOutMusicMessage.java
mediumRemote Payloadmatched "cUrl " · me/chanjar/weixin/mp/builder/outxml/MusicBuilder.java
mediumRemote Payloadmatched "cUrl " · me/chanjar/weixin/mp/builder/kefu/MusicBuilder.java

Scanned versions

VersionVerdictScoreScanned (UTC)
4.8.4-20260612.150047Review102026-06-12

Block this in CI

PkgRadar gates com.github.binarywang:weixin-java-mp (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem maven com.github.binarywang:[email protected]