Individual filenames are withheld. Each entry shows its type, its folder within the package and its own SHA-256.
POT · languages
f722ed8f8631821c…
830.4 KB
JS · assets/vendor/pro
0060bf151dc829d4…
677.1 KB
JS · assets/vendor/pro
2f62661839cf9823…
469.3 KB
SVG · assets/images/admin-flyout-menu
56b7d64d4eb603d9…
435.1 KB
PHP · libraries/composer
11099057059016d2…
406.9 KB
PHP · libraries/composer
1727238ee5793b16…
394.6 KB
JS · assets/vendor/intl-tel-input/js
74c6661b77f54b1f…
293.4 KB
SVG · assets/images/admin-flyout-menu
6ef8c5844604b856…
287.0 KB
Code signals
8 present
Observations, not findings. Every construct below appears in ordinary, legitimate plugins — they are listed so you can judge for yourself. Only ClamAV decides this package's verdict.
unserialize
Unsafe when given untrusted input
Deserialization9
base64_decode
Decodes base64 — routine, but also how packed code hides
Obfuscation7
atob
Decodes base64 in the browser
Obfuscation6
curl_exec
Makes an outbound HTTP request
Remote request4
new Function()
Builds a function from a string
Code execution2
file_get_contents(url)
Fetches a remote URL
Remote request1
assert
Can execute a string as code on old PHP
Code execution1
eval
Executes a string as code
Code execution1
Referenced hosts
20 distinct
Domains appearing in the package source. Most are documentation links or CDNs; their presence is not evidence the package contacts them.