PkgRadar

PyPI · pypi.org

pingmapper

Py Install Time Eval Exec: Python eval()/exec() called on a string.

Why PkgRadar flagged 5.4.4

SeveritySignalEvidence
mediumPy Install Time Eval ExecPython eval()/exec() called on a string. · pingmapper-5.4.4/setup.py
mediumRemote Payloadmatched "github.com/CameronBodine/PINGMapper/releases/download" · pingmapper-5.4.4/pingmapper/test_PINGMapper.py

Scanned versions

VersionVerdictScoreScanned (UTC)
5.4.6Low risk02026-06-05
5.4.5Low risk02026-06-05
5.4.4Review282026-05-27

Block this in CI

PkgRadar gates pingmapper (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi pingmapper==5.4.4