Individual filenames are withheld. Each entry shows its type, its folder within the package and its own SHA-256.
PHP · vendor/composer
d4b2313e562edf94…
16.0 KB
PHP · vendor/composer
21f4ba19e7859cb3…
15.8 KB
PHP · package root
e59acdc2e3303abc…
9.6 KB
PHP · includes/Actions
2a52bfc1e66f0a01…
5.1 KB
PHP · includes/Actions
6126c974530b0758…
4.9 KB
TXT · package root
896a5dc110729b54…
2.4 KB
PHP · vendor/composer
b26ede0d446d4575…
1.1 KB
PHP · vendor/composer
18c0e3983198ab9c…
1.1 KB
Code signals
1 present
Observations, not findings. Every construct below appears in ordinary, legitimate plugins — they are listed so you can judge for yourself. Only ClamAV decides this package's verdict.
unserialize
Unsafe when given untrusted input
Deserialization1
Referenced hosts
5 distinct
Domains appearing in the package source. Most are documentation links or CDNs; their presence is not evidence the package contacts them.