Individual filenames are withheld. Each entry shows its type, its folder within the package and its own SHA-256.
SVG · vendor/WPObjects/assets/css/fonts
ad6157926c1622ba…
434.0 KB
SVG · fonts
ad6157926c1622ba…
434.0 KB
OTF · vendor/WPObjects/assets/css/fonts
3d728043929c7f00…
253.6 KB
PNG · images
de4ba1cd4535519d…
219.4 KB
EOT · vendor/WPObjects/assets/css/fonts
d8f2e29ed1686ad4…
208.2 KB
CSS · vendor/WPObjects/assets/css/library
5d6a10d2cf439992…
195.1 KB
CSS · css
bb2bb6e985b6eb3b…
187.9 KB
PNG · images
12477fa8a0820654…
162.5 KB
Code signals
3 present
Observations, not findings. Every construct below appears in ordinary, legitimate plugins — they are listed so you can judge for yourself. Only ClamAV decides this package's verdict.
unserialize
Unsafe when given untrusted input
Deserialization2
eval
Executes a string as code
Code execution1
file_get_contents(url)
Fetches a remote URL
Remote request1
Referenced hosts
20 distinct
Domains appearing in the package source. Most are documentation links or CDNs; their presence is not evidence the package contacts them.