Observations, not findings. Every construct below appears in ordinary, legitimate plugins — they are listed so you can judge for yourself. Only ClamAV decides this package's verdict.
unserialize
Unsafe when given untrusted input
Deserialization40
assert
Can execute a string as code on old PHP
Code execution30
shell_exec
Runs an operating-system command
System command21
eval
Executes a string as code
Code execution11
exec / system
Runs an operating-system command
System command10
base64_decode
Decodes base64 — routine, but also how packed code hides
Obfuscation8
gzinflate
Decompresses a string in memory
Obfuscation2
Referenced hosts
20 distinct
Domains appearing in the package source. Most are documentation links or CDNs; their presence is not evidence the package contacts them.