PkgRadar

PyPI · pypi.org

embedxpl

Webhook Exfil Endpoint: matched "webhook.site"

Why PkgRadar flagged 3.8.1

SeveritySignalEvidence
highWebhook Exfil Endpointmatched "webhook.site" · embedxpl-3.8.1/embedxpl/modules/exploits/printers/generic/edb_51606_hp_ssrf_cve_2021_3441.py
highPy Runtime Dynamic Dangerous ImportDynamic __import__('os') — reflection bypass for static checks. · embedxpl-3.8.1/embedxpl/core/rtsp/client.py

Scanned versions

VersionVerdictScoreScanned (UTC)
3.8.1High risk752026-06-16
3.4.0High risk752026-06-02
3.3.1High risk752026-06-02
3.3.0High risk752026-06-02
3.2.1High risk752026-06-01
3.2.0High risk752026-05-30

Block this in CI

PkgRadar gates embedxpl (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi embedxpl==3.8.1