MyThemehop Writer WordPress Theme · Sep 10, 2026, 08:37 AM UTC
Cleanzip1419 entriescrc-verifiedpngphpjavascript
ZIP
5.14 MB
package size
Analysis
6 checks · 0 flagged
ClamAV 1.5.4 signature scan
3,628,051 signatures · db v28115
Undetected
ClamAV PUA heuristics
no unwanted applications
Undetected
Archive integrity
CRC verified for every entry
Valid
Path traversal (Zip Slip)
no entry escapes the extraction directory
Undetected
Encrypted content
all entries readable and scanned
None
Executable binaries
no .exe / .dll / .so / script binaries
None
Package
Theme header
Name
Writer by MyThemeShop
Version
1.2.12
Version check
Match
package and product page both state 1.2.12
Author
MyThemeShop
Author URI
https://mythemeshop.com
Project URI
https://mythemeshop.com/themes/writer
Description
Writer theme is an elegant, modern and stylish WordPress theme for writers, freelancers and authors. It has a clean design with legible fonts that keep readers focused on the content; it is ideal for all writing projects.
Individual filenames are withheld. Each entry shows its type, its folder within the package and its own SHA-256.
XML · options/demo-importer/demo-files/blog
ec1e7b7fb8ca3356…
888.3 KB
XML · options/demo-importer/demo-files/default
ec1e7b7fb8ca3356…
888.3 KB
SVG · fonts
ad6157926c1622ba…
434.0 KB
PNG · options/child-theme
53f27e0a09984732…
415.6 KB
PNG · package root
89703ed15218ca85…
333.3 KB
PNG · images
6d70d27a1cc1b0d1…
250.2 KB
PEM · functions
238823cd92d3bcdd…
208.9 KB
EOT · fonts
7bfcab6db99d5cfb…
161.9 KB
Code signals
4 present
Observations, not findings. Every construct below appears in ordinary, legitimate plugins — they are listed so you can judge for yourself. Only ClamAV decides this package's verdict.
unserialize
Unsafe when given untrusted input
Deserialization4
file_get_contents(url)
Fetches a remote URL
Remote request1
base64_decode
Decodes base64 — routine, but also how packed code hides
Obfuscation1
curl_exec
Makes an outbound HTTP request
Remote request1
Referenced hosts
20 distinct
Domains appearing in the package source. Most are documentation links or CDNs; their presence is not evidence the package contacts them.