Pub (Dart) · pub.dev
pdf_manipulator
Dart Process Http Combo: Process spawn paired with HTTP fetch — typical fetch-and-run shape.
Why PkgRadar flagged 2.0.1
| Severity | Signal | Evidence |
|---|---|---|
| medium | Dart Process Http Combo | Process spawn paired with HTTP fetch — typical fetch-and-run shape. · lib/src/hook/resolver.dart |
| medium | Dart Process Base64 Combo | Process spawn paired with base64Decode — possible obfuscated payload. · tool/generate_fixtures.dart |
| medium | Remote Payload | matched "github.com/$_repo/releases/download" · hook/build.dart |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
2.0.1 | Review | 48 | 2026-06-15 |
2.0.1-dev.0 | Review | 48 | 2026-06-15 |
2.0.0 | Review | 48 | 2026-06-14 |
2.0.0-dev.0 | Review | 48 | 2026-06-14 |
1.0.6 | Review | 30 | 2026-06-09 |
1.0.6-dev.0 | Review | 30 | 2026-06-09 |
1.0.5 | Review | 30 | 2026-06-05 |
1.0.5-dev.0 | Review | 30 | 2026-06-05 |
1.0.4-dev.0 | Review | 30 | 2026-06-05 |
1.0.4 | Review | 30 | 2026-06-05 |
1.0.3 | Review | 42 | 2026-06-05 |
1.0.3-dev.0 | Review | 42 | 2026-06-05 |
1.0.2 | Review | 42 | 2026-06-05 |
1.0.2-dev.0 | Review | 42 | 2026-06-05 |
1.0.1 | Review | 42 | 2026-06-05 |
1.0.0 | Review | 42 | 2026-06-03 |
1.0.0-dev.0 | Review | 42 | 2026-06-03 |
Block this in CI
pkgradar gate --ecosystem pub [email protected]