{
  "ml": {
    "v": "7",
    "id": 2525,
    "lvl": -1,
    "conf": 0,
    "prob": 0.00003898143768310547,
    "type": "zip",
    "version": "v18.18",
    "analyzed_at": "2026-09-25T17:19:34Z"
  },
  "path": "dotenv@v6.4.13",
  "raw": {
    "rev": "c1ea9",
    "files": [
      {
        "id": 2525,
        "mol": "K(Li₂)O₂(C₂Xe)H₄(Cm₂Db₂F₂Os₂)Md₃(In₆Pa)",
        "pid": 192,
        "rel": "fetched",
        "sha": "f158faaf3979bccdbb81e4505215d127c50ce57277a71d8a142962f1d62aa56c",
        "via": "https://api.github.com/repos/symfony/dotenv/zipball/436ae2dd89360fea8c7d5ff3f48ecf523c80bfb4",
        "path": "pkg:composer/symfony/dotenv@v6.4.13",
        "risk": 15,
        "size": 14658,
        "type": "zip",
        "depth": 2,
        "facts": {
          "metrics": {
            "file": {
              "size": 14658,
              "entropy": 7.84
            },
            "binary": {
              "peak_region_bytes": 13312,
              "peak_region_entropy": 7.83
            },
            "archive": {
              "file_count": 11,
              "has_comment": 1,
              "comment_size": 40,
              "member_count": 14,
              "script_count": 7,
              "zip_bomb_ratio": 4.42,
              "compressed_size": 12144,
              "directory_count": 3,
              "executable_count": 0,
              "extra_field_size": 126,
              "noise_file_count": 0,
              "compression.ratio": 0.31,
              "hidden_file_count": 0,
              "uncompressed_size": 39794,
              "crc_collision_count": 0,
              "entry_comment_count": 0,
              "max_filename_length": 59,
              "rtlo_filename_count": 0,
              "format.regular_count": 11,
              "nested_archive_count": 0,
              "path_traversal_count": 0,
              "symlink_escape_count": 0,
              "security.setgid_count": 0,
              "security.setuid_count": 0,
              "security.sticky_count": 0,
              "double_extension_count": 0,
              "duplicate_member_count": 0,
              "format.directory_count": 3,
              "security.symlink_count": 0,
              "unicode_filename_count": 0,
              "homoglyph_filename_count": 0,
              "security.encrypted_count": 0,
              "timing.mtime_unique_count": 1,
              "timing.mtime_unique_ratio": 0.07,
              "misplaced_executable_count": 0,
              "timing.mtime_dominant_count": 14,
              "timing.mtime_spread_seconds": 0,
              "timing.sentinel_mtime_count": 0,
              "security.world_writable_count": 0,
              "timing.mtime_dominant_fraction": 1,
              "compression.method_counts.stored": 3,
              "compression.method_counts.deflate": 11
            }
          }
        },
        "traits": [
          {
            "id": "metadata/import/php/symfony/component/console/command/command::symfony/component/console/command/command",
            "conf": 0.95,
            "crit": 2,
            "desc": "imports Symfony\\Component\\Console\\Command\\Command",
            "from": [
              {
                "file": 2
              }
            ]
          },
          {
            "id": "well-known/lib/web/symfony::symfony-console-attribute",
            "conf": 0.93,
            "crit": 3,
            "desc": "Uses Symfony AsCommand attribute",
            "from": [
              {
                "file": 2
              }
            ]
          },
          {
            "id": "objectives/command-and-control/backdoor/webshell/ui::self-named-get-form--rx-4",
            "mbc": "B0030",
            "conf": 0.86,
            "crit": 3,
            "desc": "Matches '$_SERVER['",
            "from": [
              {
                "file": 2
              }
            ]
          },
          {
            "id": "metadata/import/php/symfony/component/console/output/outputinterface::symfony/component/console/output/outputinterface",
            "conf": 0.95,
            "crit": 2,
            "desc": "imports Symfony\\Component\\Console\\Output\\OutputInterface",
            "from": [
              {
                "file": 2
              }
            ]
          },
          {
            "id": "micro-behaviors/os/env/read::php-getenv-call",
            "conf": 0.85,
            "crit": 3,
            "desc": "Calls PHP getenv",
            "from": [
              {
                "file": 4
              }
            ]
          },
          {
            "id": "micro-behaviors/communications/http/url/forge::public-code-forge-url",
            "conf": 0.9,
            "crit": 3,
            "desc": "References a public code-forge URL",
            "from": [
              {
                "file": 10
              }
            ]
          },
          {
            "id": "micro-behaviors/data/string/replace::php-preg-replace-call",
            "conf": 0.9,
            "crit": 3,
            "desc": "PHP replaces strings with a regular expression",
            "from": [
              {
                "file": 4
              }
            ]
          },
          {
            "id": "metadata/lang/natural::lang-english--atom-3",
            "conf": 0.8,
            "crit": 1,
            "desc": "English function-word token \"that\"",
            "from": [
              {
                "file": 1
              }
            ]
          },
          {
            "id": "well-known/lib/web/symfony::symfony-context",
            "conf": 0.93,
            "crit": 3,
            "desc": "File runs inside the Symfony framework",
            "from": [
              {
                "off": 283,
                "file": 2527,
                "line": 14
              },
              {
                "off": 283,
                "file": 2528,
                "line": 14
              },
              {
                "file": 2529
              }
            ],
            "uses": [
              1,
              24,
              36
            ]
          },
          {
            "id": "micro-behaviors/communications/http/upload::php-script-extension-token",
            "conf": 0.9,
            "crit": 1,
            "desc": "PHP server-script extension token",
            "from": [
              {
                "file": 2
              }
            ]
          },
          {
            "id": "micro-behaviors/communications/http/client/file-read::php-file-get-variable-source",
            "conf": 0.88,
            "crit": 3,
            "desc": "PHP reads content from a variable source",
            "from": [
              {
                "file": 2
              }
            ]
          },
          {
            "id": "metadata/import/php/symfony/component/dotenv/dotenv::symfony/component/dotenv/dotenv",
            "conf": 0.95,
            "crit": 3,
            "desc": "imports Symfony\\Component\\Dotenv\\Dotenv",
            "from": [
              {
                "file": 2
              }
            ]
          },
          {
            "id": "objectives/command-and-control/dropper/execution/jphp::jphp-file-put-contents",
            "conf": 0.9,
            "crit": 3,
            "desc": "JPHP file write call",
            "from": [
              {
                "file": 3
              }
            ]
          },
          {
            "id": "metadata/lang/generated::automatically-generated-source-marker",
            "conf": 0.85,
            "crit": 2,
            "desc": "Generated source provenance marker",
            "from": [
              {
                "file": 3
              }
            ]
          },
          {
            "id": "metadata/import/php/symfony/component/console/input/inputoption::symfony/component/console/input/inputoption",
            "conf": 0.95,
            "crit": 2,
            "desc": "imports Symfony\\Component\\Console\\Input\\InputOption",
            "from": [
              {
                "file": 3
              }
            ]
          },
          {
            "id": "metadata/lang/natural::lang-english--atom-6",
            "conf": 0.8,
            "crit": 1,
            "desc": "English function-word token \"with\"",
            "from": [
              {
                "file": 1
              }
            ]
          },
          {
            "id": "metadata/import/php/symfony/component/process/exception/exceptioninterface::symfony/component/process/exception/exceptioninterface",
            "conf": 0.95,
            "crit": 3,
            "desc": "imports Symfony\\Component\\Process\\Exception\\ExceptionInterface",
            "from": [
              {
                "file": 4
              }
            ]
          },
          {
            "id": "micro-behaviors/fs/write/file/full::php-file-put-contents",
            "atk": "T1546",
            "conf": 1.0,
            "crit": 3,
            "desc": "Calls PHP file_put_contents()",
            "from": [
              {
                "file": 3
              }
            ]
          },
          {
            "id": "metadata/lang/natural::lang-english--atom-7",
            "conf": 0.8,
            "crit": 1,
            "desc": "English function-word token \"this\"",
            "from": [
              {
                "file": 1
              }
            ]
          },
          {
            "id": "metadata/import/php/symfony/component/console/input/inputargument::symfony/component/console/input/inputargument",
            "conf": 0.95,
            "crit": 2,
            "desc": "imports Symfony\\Component\\Console\\Input\\InputArgument",
            "from": [
              {
                "file": 2
              }
            ]
          },
          {
            "id": "well-known/lib/web/symfony::package-doc",
            "conf": 0.96,
            "crit": 2,
            "desc": "Symfony package doc marker",
            "from": [
              {
                "file": 2
              }
            ]
          },
          {
            "id": "micro-behaviors/data/string/replace::php-str-replace-call",
            "conf": 0.9,
            "crit": 3,
            "desc": "PHP replaces matched string content",
            "from": [
              {
                "file": 4
              }
            ]
          },
          {
            "id": "micro-behaviors/os/sysinfo/platform/string::os-string-windows",
            "conf": 0.4,
            "crit": 2,
            "desc": "Windows platform string",
            "from": [
              {
                "file": 4
              }
            ]
          },
          {
            "id": "well-known/lib/web/laravel::laravel-context",
            "conf": 0.9,
            "crit": 3,
            "desc": "File runs inside the Laravel framework",
            "from": [
              {
                "file": 2527
              },
              {
                "file": 2528
              }
            ],
            "uses": [
              30
            ]
          },
          {
            "id": "well-known/lib/web/symfony::symfony-console-command-extends",
            "conf": 0.93,
            "crit": 3,
            "desc": "Extends Symfony Console Command base class",
            "from": [
              {
                "file": 2
              }
            ]
          },
          {
            "id": "metadata/import/php/symfony/component/process/process::symfony/component/process/process",
            "conf": 0.95,
            "crit": 3,
            "desc": "imports Symfony\\Component\\Process\\Process",
            "from": [
              {
                "file": 4
              }
            ]
          },
          {
            "id": "metadata/import/php/symfony/component/console/completion/completioninput::symfony/component/console/completion/completioninput",
            "conf": 0.95,
            "crit": 2,
            "desc": "imports Symfony\\Component\\Console\\Completion\\CompletionInput",
            "from": [
              {
                "file": 2
              }
            ]
          },
          {
            "id": "metadata/import/php/symfony/component/console/input/inputinterface::symfony/component/console/input/inputinterface",
            "conf": 0.95,
            "crit": 2,
            "desc": "imports Symfony\\Component\\Console\\Input\\InputInterface",
            "from": [
              {
                "file": 2
              }
            ]
          },
          {
            "id": "micro-behaviors/os/env/read::php-server-superglobal",
            "conf": 0.85,
            "crit": 3,
            "desc": "Reads PHP $_SERVER execution environment data",
            "from": [
              {
                "file": 2
              }
            ]
          },
          {
            "id": "well-known/lib/web/symfony::symfony-framework",
            "conf": 0.97,
            "crit": 3,
            "desc": "Symfony PHP framework component",
            "from": [
              {
                "file": 2527
              },
              {
                "file": 2528
              },
              {
                "file": 2529
              },
              {
                "file": 2530
              },
              {
                "file": 2531
              },
              {
                "file": 2532
              },
              {
                "file": 2533
              }
            ],
            "uses": [
              20
            ]
          },
          {
            "id": "well-known/lib/web/laravel::laravel-artisan-command-class",
            "conf": 0.9,
            "crit": 3,
            "desc": "Extends Laravel Console\\Command",
            "from": [
              {
                "file": 2
              }
            ]
          },
          {
            "id": "metadata/import/php/processexception::processexception",
            "conf": 0.95,
            "crit": 2,
            "desc": "imports ProcessException",
            "from": [
              {
                "file": 4
              }
            ]
          },
          {
            "id": "micro-behaviors/fs/path/secret-config::dotenv-filename-literal",
            "atk": "T1552.001",
            "conf": 0.85,
            "crit": 1,
            "desc": ".env filename literal",
            "from": [
              {
                "file": 2
              }
            ]
          },
          {
            "id": "metadata/import/php/symfony/component/console/attribute/ascommand::symfony/component/console/attribute/ascommand",
            "conf": 0.95,
            "crit": 2,
            "desc": "imports Symfony\\Component\\Console\\Attribute\\AsCommand",
            "from": [
              {
                "file": 2
              }
            ]
          },
          {
            "id": "metadata/import/php/symfony/component/dotenv/exception/formatexceptioncontext::symfony/component/dotenv/exception/formatexceptioncontext",
            "conf": 0.95,
            "crit": 3,
            "desc": "imports Symfony\\Component\\Dotenv\\Exception\\FormatExceptionContext",
            "from": [
              {
                "file": 4
              }
            ]
          },
          {
            "id": "metadata/import/php/symfony/component/console/completion/completionsuggestions::symfony/component/console/completion/completionsuggestions",
            "conf": 0.95,
            "crit": 2,
            "desc": "imports Symfony\\Component\\Console\\Completion\\CompletionSuggestions",
            "from": [
              {
                "file": 2
              }
            ]
          },
          {
            "id": "well-known/lib/web/symfony::symfony-component-import",
            "conf": 0.93,
            "crit": 3,
            "desc": "Imports a Symfony Component namespace",
            "from": [
              {
                "file": 2
              }
            ]
          },
          {
            "id": "metadata/import/php/symfony/component/console/formatter/outputformatter::symfony/component/console/formatter/outputformatter",
            "conf": 0.95,
            "crit": 2,
            "desc": "imports Symfony\\Component\\Console\\Formatter\\OutputFormatter",
            "from": [
              {
                "file": 2
              }
            ]
          },
          {
            "id": "metadata/import/php/symfony/component/console/style/symfonystyle::symfony/component/console/style/symfonystyle",
            "conf": 0.95,
            "crit": 2,
            "desc": "imports Symfony\\Component\\Console\\Style\\SymfonyStyle",
            "from": [
              {
                "file": 2
              }
            ]
          },
          {
            "id": "metadata/lang/natural::lang-english--atom-5",
            "conf": 0.8,
            "crit": 1,
            "desc": "English function-word token \"for\"",
            "from": [
              {
                "file": 1
              }
            ]
          },
          {
            "id": "objectives/execution/interpreter/php-assert::server-superglobal-read",
            "atk": "T1505.003,T1059.006",
            "mbc": "B0030",
            "conf": 0.85,
            "crit": 3,
            "desc": "Reads the server superglobal",
            "from": [
              {
                "file": 2
              }
            ]
          },
          {
            "id": "metadata/import/php/symfony/component/dotenv/exception/pathexception::symfony/component/dotenv/exception/pathexception",
            "conf": 0.95,
            "crit": 3,
            "desc": "imports Symfony\\Component\\Dotenv\\Exception\\PathException",
            "from": [
              {
                "file": 4
              }
            ]
          },
          {
            "id": "metadata/lang/natural::lang-english--atom-1",
            "conf": 0.8,
            "crit": 1,
            "desc": "English function-word token \"the\"",
            "from": [
              {
                "file": 1
              }
            ]
          },
          {
            "id": "metadata/import/php/symfony/component/dotenv/exception/formatexception::symfony/component/dotenv/exception/formatexception",
            "conf": 0.95,
            "crit": 3,
            "desc": "imports Symfony\\Component\\Dotenv\\Exception\\FormatException",
            "from": [
              {
                "file": 4
              }
            ]
          },
          {
            "id": "metadata/import/php/symfony/component/dependencyinjection/attribute/autoconfigure::symfony/component/dependencyinjection/attribute/autoconfigure",
            "conf": 0.95,
            "crit": 2,
            "desc": "imports Symfony\\Component\\DependencyInjection\\Attribute\\Autoconfigure",
            "from": [
              {
                "file": 3
              }
            ]
          },
          {
            "id": "metadata/lang/natural::lang-english--atom-2",
            "conf": 0.8,
            "crit": 1,
            "desc": "English function-word token \"and\"",
            "from": [
              {
                "file": 1
              }
            ]
          },
          {
            "id": "micro-behaviors/os/callback/dispatch::php-regex-callback-api",
            "conf": 0.9,
            "crit": 3,
            "desc": "Calls PHP regex callback replacement API",
            "from": [
              {
                "file": 4
              }
            ]
          },
          {
            "id": "micro-behaviors/fs/path/construct::php-script-path-suffix",
            "conf": 0.94,
            "crit": 3,
            "desc": "PHP script path suffix",
            "from": [
              {
                "file": 2
              }
            ]
          },
          {
            "id": "micro-behaviors/communications/email/address::google-consumer-email-domain-suffix",
            "conf": 0.55,
            "crit": 3,
            "desc": "Gmail consumer email domain suffix",
            "from": [
              {
                "file": 4
              }
            ]
          },
          {
            "id": "micro-behaviors/data/serialize/json::php-json-decode",
            "conf": 0.9,
            "crit": 3,
            "desc": "PHP JSON deserialization",
            "from": [
              {
                "file": 3
              }
            ]
          },
          {
            "id": "metadata/file/archive::archive-at-least-10-members",
            "conf": 0.9,
            "crit": 3,
            "desc": "Archive contains at least ten members"
          },
          {
            "id": "metadata/package/testing/scripted::go-fuzz-corpus-entry-basename",
            "conf": 0.96,
            "crit": 3,
            "desc": "Go fuzz corpus entry basename (sha1[-index])"
          },
          {
            "id": "metadata/file/naming::hex-hash-zip-basename",
            "conf": 0.92,
            "crit": 3,
            "desc": "Zip basename is a hexadecimal hash"
          }
        ]
      }
    ]
  }
}