PkgRadar

PyPI · pypi.org

phonofix

Remote Payload: matched "curl "

Why PkgRadar flagged 0.4.0

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · phonofix-0.4.0/scripts/setup_espeak.sh

Scanned versions

VersionVerdictScoreScanned (UTC)
0.4.0Review122026-05-26

Block this in CI

PkgRadar gates phonofix (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi phonofix==0.4.0