An advanced toolkit for placing in-store orders through a WooCommerce based Point of Sale (POS) interface. Requires <a href="http://wordpress.org/plugins/woocommerce/">WooCommerce</a>.
Individual filenames are withheld. Each entry shows its type, its folder within the package and its own SHA-256.
JS · packages/app/dist
…
3.92 MB
JS · packages/receipt/dist
d2d0bc5525c550af…
1.45 MB
JS · packages/app/dist/assets
3f66c43b37039cbd…
1.01 MB
JS · packages/receipt/dist
108502444a002206…
1023.1 KB
CSS · packages/app/dist/assets
8aeed60f32249efe…
631.4 KB
WOFF · packages/app/dist/assets
28c8f97fd46b1a47…
569.8 KB
TTF · packages/app/dist/assets
4ea5c3ff563052c2…
409.9 KB
WOFF2 · packages/app/dist/assets
310101948abf89e0…
391.1 KB
Code signals
6 present
Observations, not findings. Every construct below appears in ordinary, legitimate plugins — they are listed so you can judge for yourself. Only ClamAV decides this package's verdict.
curl_exec
Makes an outbound HTTP request
Remote request3
new Function()
Builds a function from a string
Code execution2
shell_exec
Runs an operating-system command
System command2
exec / system
Runs an operating-system command
System command1
atob
Decodes base64 in the browser
Obfuscation1
base64_decode
Decodes base64 — routine, but also how packed code hides
Obfuscation1
Referenced hosts
20 distinct
Domains appearing in the package source. Most are documentation links or CDNs; their presence is not evidence the package contacts them.