Individual filenames are withheld. Each entry shows its type, its folder within the package and its own SHA-256.
JS · assets/js
02a452513d20180c…
386.9 KB
PHP · includes
fabced19bb04b3fb…
320.6 KB
PHP · includes
12e87102bd9beb3c…
250.7 KB
PHP · includes
0a60947dd122da65…
150.2 KB
JS · assets/js
91638e0f45791a6b…
142.8 KB
PHP · includes
b867a594258ae497…
139.6 KB
POT · languages
c25972c54b0e551e…
96.7 KB
PHP · includes
7004484cf21da6f7…
72.3 KB
Code signals
5 present
Observations, not findings. Every construct below appears in ordinary, legitimate plugins — they are listed so you can judge for yourself. Only ClamAV decides this package's verdict.
base64_decode
Decodes base64 — routine, but also how packed code hides
Obfuscation5
curl_exec
Makes an outbound HTTP request
Remote request2
gzinflate
Decompresses a string in memory
Obfuscation1
file_get_contents(url)
Fetches a remote URL
Remote request1
unserialize
Unsafe when given untrusted input
Deserialization1
Referenced hosts
20 distinct
Domains appearing in the package source. Most are documentation links or CDNs; their presence is not evidence the package contacts them.