SupportCandy Slack integration · Sep 07, 2026, 08:08 AM UTC
Cleanzip103 entriescrc-verifiedphppomo
ZIP
0.08 MB
package size
Analysis
6 checks · 0 flagged
ClamAV 1.5.4 signature scan
3,628,051 signatures · db v28115
Undetected
ClamAV PUA heuristics
no unwanted applications
Undetected
Archive integrity
CRC verified for every entry
Valid
Path traversal (Zip Slip)
no entry escapes the extraction directory
Undetected
Encrypted content
all entries readable and scanned
None
Executable binaries
no .exe / .dll / .so / script binaries
None
Package
Plugin header
Name
SupportCandy - Slack integration
Version
3.0.8
Version check
Match
package and product page both state 3.0.8
Author
SupportCandy
Author URI
https://supportcandy.net
Project URI
https://supportcandy.net
Description
Send notifications to your slack channel whenever you receive a new ticket or reply to the ticket. Members of the slack channel can directly reply to slack notification to post reply within the ticket.
Individual filenames are withheld. Each entry shows its type, its folder within the package and its own SHA-256.
PHP · includes
73bc64699fddab5a…
12.4 KB
MD · vendor-prefixed/league/html-to-markdown
9b9366a182e79df4…
12.1 KB
PHP · vendor-prefixed/league/html-to-markdown/src
6a3cf32876e75a23…
10.0 KB
PHP · includes
97e7aca40b4195fa…
10.0 KB
MD · vendor-prefixed/league/html-to-markdown
fa3084fdac18a960…
9.7 KB
PHP · vendor-prefixed/league/html-to-markdown/src
fc9366bf898b941b…
5.5 KB
PHP · includes
6407231a3052a6cc…
5.5 KB
PHP · package root
34c61939e94816c1…
4.9 KB
Code signals
1 present
Observations, not findings. Every construct below appears in ordinary, legitimate plugins — they are listed so you can judge for yourself. Only ClamAV decides this package's verdict.
assert
Can execute a string as code on old PHP
Code execution10
Referenced hosts
17 distinct
Domains appearing in the package source. Most are documentation links or CDNs; their presence is not evidence the package contacts them.