PkgRadar

PyPI · pypi.org

pdftl

Remote Payload: matched "curl "

Why PkgRadar flagged 0.21.1

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · pdftl-0.21.1/tools/install_php_ci_prereqs.sh
mediumRemote Payloadmatched "curl " · pdftl-0.21.1/tools/update_portfile.sh

Scanned versions

VersionVerdictScoreScanned (UTC)
0.21.1Review162026-06-14
0.21.0Review162026-06-12
0.20.0Review242026-06-07
0.19.0Review242026-06-01
0.18.1Review242026-05-29

Block this in CI

PkgRadar gates pdftl (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi pdftl==0.21.1