01
Why does this matter to us?
Known CVEs are only part of the risk. New or compromised packages can contain malicious install scripts, obfuscated code or hidden payloads before any public advisory exists.
Workshop · Pre-release
A local security scanner that checks Composer packages for backdoors, obfuscation, unexpected binaries and other supply-chain indicators before installation.
How can suspicious behavior in new PHP dependencies be detected before third-party code becomes part of an application?
01
Known CVEs are only part of the risk. New or compromised packages can contain malicious install scripts, obfuscated code or hidden payloads before any public advisory exists.
02
The Composer plugin and CLI workflow combines AST rules, heuristics, archive inspection, YARA-compatible rules and integrity evidence. Scans run locally without default telemetry or source-code uploads.
03
The scanner, plugin, CLI, output formats, cache, integrity checks and a broad test suite are present. The project is deliberately classified as version 0.1.0 and not yet as a stable release.
04
Complete release keys and the installation matrix, build a robust golden corpus and move isolation of third-party rules out of process.