Extuno scans the composer.json hook before composer install runs it.
A composer.json install hook fires before your autoloader ever touches the package. Extuno diffs each version, then runs static and AI analysis on the PHP for install-script RCE, backdoors, and webshells.
composer package
Every finding is backed by evidence.
Each finding names the change, why it is dangerous, and the recommended action.
Install-script RCE
A composer.json post-install hook runs curl|bash on `composer install`.
Injected webshell
A file gains eval() over request data. That is a remote-controlled shell.
Remote code loader
The package fetches a URL and eval()s the response.
Install-time PHP, caught before composer runs it
Extuno reads the composer.json hooks and the PHP, and flags the download-and-run install command.
- + Vulnerability and secret-leak testing on every version
- + Static analysis reads the package without running it
- + AI code analysis reads the full source and correlates the change against prior versions
Scan your first Composer package free.
5 free credits on signup. One credit per scan, no card required.
Common questions
Does Extuno support Composer?
Yes. Extuno scans Composer with static analysis, and AI code analysis, and diffs every version to catch one that was clean but poisoned through an update.
How does Extuno scan Composer?
Extuno acquires the published Composer artifact, reads it statically with 1100+ rules, reviews the source with AI, and diffs it against the prior version. The finding names the file, the change, why it is dangerous, and the fix.
What does Extuno catch in Composer?
Leaked secrets, obfuscated or malicious code, dangerous permissions and APIs, exfiltration and command-and-control behavior, and the headline signal: a version that turns malicious after an update.