Individual filenames are withheld. Each entry shows its type, its folder within the package and its own SHA-256.
JS · assets/js/admin/woocommerce
0982c0fc0319f503…
545.7 KB
SVG · plugin-fw/assets/fonts/font-awesome
ad6157926c1622ba…
434.0 KB
JPG · assets/images/single
ead2910c628c3d59…
230.8 KB
JS · plugin-fw/assets/js/codemirror
a307856bdbdea270…
221.4 KB
EOT · plugin-fw/assets/fonts/font-awesome
7bfcab6db99d5cfb…
161.9 KB
TTF · plugin-fw/assets/fonts/font-awesome
aa58f33f239a0fb0…
161.7 KB
JS · plugin-fw/dist/lapilli-ui/components
99f43f3b23bd736a…
135.2 KB
CSS · plugin-fw/assets/css
3e0ec855206502f9…
129.5 KB
Code signals
2 present
Observations, not findings. Every construct below appears in ordinary, legitimate plugins — they are listed so you can judge for yourself. Only ClamAV decides this package's verdict.
file_get_contents(url)
Fetches a remote URL
Remote request1
unserialize
Unsafe when given untrusted input
Deserialization1
Referenced hosts
20 distinct
Domains appearing in the package source. Most are documentation links or CDNs; their presence is not evidence the package contacts them.