Individual filenames are withheld. Each entry shows its type, its folder within the package and its own SHA-256.
JS · assets/vendor/ace
f401da800ef47af3…
1.53 MB
TTF · assets/vendor/lucide
e87331bfb8f04419…
636.7 KB
JS · assets/vendor/ace
d2a6002b06fc6e60…
472.6 KB
JS · assets/vendor/ace
0d6cc952fe0291d8…
468.2 KB
JS · assets/vendor/ace
fe0eccf6fc67bac8…
349.1 KB
JS · assets/vendor/ace
03cae9feabea7c6d…
320.6 KB
WOFF · assets/vendor/lucide
9aaa2d1bd2c9f35e…
293.2 KB
JS · assets/vendor/ace
33feef441021d55b…
227.5 KB
Code signals
3 present
Observations, not findings. Every construct below appears in ordinary, legitimate plugins — they are listed so you can judge for yourself. Only ClamAV decides this package's verdict.
unserialize
Unsafe when given untrusted input
Deserialization12
new Function()
Builds a function from a string
Code execution3
eval (JavaScript)
Executes a string as code
Code execution3
Referenced hosts
20 distinct
Domains appearing in the package source. Most are documentation links or CDNs; their presence is not evidence the package contacts them.