Individual filenames are withheld. Each entry shows its type, its folder within the package and its own SHA-256.
JS · assets/js/handsontable
…
3.56 MB
JS · assets/js/handsontable
44c1e51041956647…
1.04 MB
JS · assets/js/export-tools
7bae410073091f63…
1.03 MB
PO · languages/el
650dbdfdae070c0c…
876.8 KB
JS · assets/js/handsontable
b2c573c84f480547…
868.5 KB
PO · languages/ru_RU
e4a721ab7f1865b3…
858.5 KB
PO · languages/fr_FR
56bb4c9b23741cda…
750.5 KB
PO · languages/hu_HU
6e7189caa8045cfe…
744.9 KB
Code signals
10 present
Observations, not findings. Every construct below appears in ordinary, legitimate plugins — they are listed so you can judge for yourself. Only ClamAV decides this package's verdict.
new Function()
Builds a function from a string
Code execution12
unserialize
Unsafe when given untrusted input
Deserialization9
base64_decode
Decodes base64 — routine, but also how packed code hides
Obfuscation9
assert
Can execute a string as code on old PHP
Code execution8
atob
Decodes base64 in the browser
Obfuscation6
curl_exec
Makes an outbound HTTP request
Remote request3
eval
Executes a string as code
Code execution3
eval (JavaScript)
Executes a string as code
Code execution2
exec / system
Runs an operating-system command
System command1
gzinflate
Decompresses a string in memory
Obfuscation1
Referenced hosts
20 distinct
Domains appearing in the package source. Most are documentation links or CDNs; their presence is not evidence the package contacts them.