Individual filenames are withheld. Each entry shows its type, its folder within the package and its own SHA-256.
JS · assets
c676a2823fbc3b62…
1.13 MB
JS · assets
35399e6838299068…
1.03 MB
JS · assets
7d22a79aad82bc8a…
779.9 KB
JS · assets
395e97794b5fad5c…
761.8 KB
JSON · backend/data
5e1e5d1e92a435cd…
407.4 KB
JS · assets
7c0480064fcfb5ec…
341.7 KB
PHP · vendor/composer
e39439747aaad048…
259.3 KB
PHP · vendor/nesbot/carbon/src/Carbon
0b98eb7bbcf33fc4…
241.6 KB
Code signals
7 present
Observations, not findings. Every construct below appears in ordinary, legitimate plugins — they are listed so you can judge for yourself. Only ClamAV decides this package's verdict.
unserialize
Unsafe when given untrusted input
Deserialization9
base64_decode
Decodes base64 — routine, but also how packed code hides
Obfuscation8
exec / system
Runs an operating-system command
System command2
new Function()
Builds a function from a string
Code execution1
file_get_contents(url)
Fetches a remote URL
Remote request1
assert
Can execute a string as code on old PHP
Code execution1
eval
Executes a string as code
Code execution1
Referenced hosts
20 distinct
Domains appearing in the package source. Most are documentation links or CDNs; their presence is not evidence the package contacts them.