PyPI · pypi.org
kwebsp
Py Install Time Os System: Direct shell invocation via os.system / os.popen / os.exec*.
Why PkgRadar flagged 1.52
| Severity | Signal | Evidence |
|---|---|---|
| high | Py Install Time Os System | Direct shell invocation via os.system / os.popen / os.exec*. · kwebsp-1.52/kwebsp/index/controller/index/setup.py |
| medium | Py Install Time Subprocess | subprocess call with shell=True — passes argv to /bin/sh. · kwebsp-1.52/kwebsp/index/controller/index/setup.py |
| high | Py Import Time Raw Socket | Raw socket creation at install or import time. · kwebsp-1.52/kwebsp/common/__init__.py |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
1.52 | High risk | 110 | 2026-06-16 |
1.51 | High risk | 110 | 2026-06-14 |
1.50 | High risk | 110 | 2026-06-13 |
1.49 | High risk | 110 | 2026-06-12 |
1.48 | High risk | 110 | 2026-06-12 |
1.47 | High risk | 110 | 2026-06-12 |
1.46 | High risk | 110 | 2026-06-12 |
1.45 | High risk | 110 | 2026-06-11 |
1.44 | High risk | 110 | 2026-06-11 |
1.43 | High risk | 110 | 2026-06-11 |
1.42 | High risk | 110 | 2026-06-10 |
1.41 | High risk | 110 | 2026-06-09 |
1.40 | High risk | 110 | 2026-06-08 |
1.39 | High risk | 110 | 2026-06-08 |
1.38 | High risk | 110 | 2026-06-08 |
1.37 | High risk | 110 | 2026-06-07 |
1.36 | High risk | 110 | 2026-06-07 |
1.35 | High risk | 110 | 2026-06-07 |
1.34 | High risk | 110 | 2026-06-07 |
1.33 | High risk | 110 | 2026-06-07 |
1.32 | High risk | 110 | 2026-06-07 |
1.31 | High risk | 110 | 2026-06-07 |
1.30 | High risk | 110 | 2026-06-06 |
1.29 | High risk | 110 | 2026-06-05 |
1.28 | High risk | 60 | 2026-05-30 |
1.27 | High risk | 60 | 2026-05-30 |
Block this in CI
pkgradar gate --ecosystem pypi kwebsp==1.52