← All experiments

Workshop · Pre-release

pharscout: Security before composer install

A local security scanner that checks Composer packages for backdoors, obfuscation, unexpected binaries and other supply-chain indicators before installation.

Experiment status
Pre-release
Area of inquiry
Supply-chain checks for PHP packages
Outcome
Potential product path

What are we trying to find out?

How can suspicious behavior in new PHP dependencies be detected before third-party code becomes part of an application?

01

Why does this matter to us?

Known CVEs are only part of the risk. New or compromised packages can contain malicious install scripts, obfuscated code or hidden payloads before any public advisory exists.

02

What did we build?

The Composer plugin and CLI workflow combines AST rules, heuristics, archive inspection, YARA-compatible rules and integrity evidence. Scans run locally without default telemetry or source-code uploads.

03

Where does the experiment stand?

The scanner, plugin, CLI, output formats, cache, integrity checks and a broad test suite are present. The project is deliberately classified as version 0.1.0 and not yet as a stable release.

04

What happens next?

Complete release keys and the installation matrix, build a robust golden corpus and move isolation of third-party rules out of process.

Technologies and topics

  • PHP
  • Composer
  • Supply Chain
  • YARA
  • Static Analysis
  • Security