PkgRadar

PyPI · pypi.org

websec-validator

Remote Payload: matched "curl "

Why PkgRadar flagged 0.5.0

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · websec_validator-0.5.0/src/websec_validator/templates/probes/appsync-introspection.sh
mediumRemote Payloadmatched "curl " · websec_validator-0.5.0/src/websec_validator/templates/probes/bola-cross-tenant.sh
mediumRemote Payloadmatched "curl " · websec_validator-0.5.0/src/websec_validator/templates/probes/client-integrity-checklist.sh
mediumRemote Payloadmatched "curl " · websec_validator-0.5.0/src/websec_validator/templates/probes/error-disclosure-probe.sh
mediumRemote Payloadmatched "curl " · websec_validator-0.5.0/src/websec_validator/templates/probes/forged-token.sh
mediumRemote Payloadmatched "curl " · websec_validator-0.5.0/src/websec_validator/templates/probes/jwt-attacks.sh
mediumRemote Payloadmatched "curl " · websec_validator-0.5.0/src/websec_validator/templates/probes/password-reuse.sh
mediumRemote Payloadmatched "curl " · websec_validator-0.5.0/src/websec_validator/templates/probes/pii-output-diff.sh
mediumRemote Payloadmatched "curl " · websec_validator-0.5.0/src/websec_validator/templates/probes/rate-limit-burst.sh
mediumRemote Payloadmatched "curl " · websec_validator-0.5.0/src/websec_validator/templates/probes/s3-assess.sh
mediumRemote Payloadmatched "curl " · websec_validator-0.5.0/src/websec_validator/templates/probes/ssrf-probes.sh
mediumRemote Payloadmatched "curl " · websec_validator-0.5.0/src/websec_validator/templates/probes/unauth-baseline.sh

Scanned versions

VersionVerdictScoreScanned (UTC)
0.5.0High risk502026-06-12
0.4.2High risk502026-06-10
0.4.1High risk502026-06-10
0.4.0High risk502026-06-10
0.3.0High risk502026-06-07
0.2.9High risk502026-06-01
0.2.8High risk502026-06-01
0.2.7High risk502026-06-01
0.2.6High risk502026-06-01
0.2.5High risk502026-06-01
0.2.4High risk502026-05-31
0.2.3High risk502026-05-31
0.2.2High risk502026-05-31
0.2.1High risk502026-05-31
0.2.0High risk502026-05-31

Block this in CI

PkgRadar gates websec-validator (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi websec-validator==0.5.0