MyThemehop MyPortfolio WordPress Theme · Sep 10, 2026, 08:36 AM UTC
Cleanzip1744 entriescrc-verifiedpngphppo
ZIP
6.45 MB
package size
Analysis
6 checks · 0 flagged
ClamAV 1.5.4 signature scan
3,628,051 signatures · db v28115
Undetected
ClamAV PUA heuristics
no unwanted applications
Undetected
Archive integrity
CRC verified for every entry
Valid
Path traversal (Zip Slip)
no entry escapes the extraction directory
Undetected
Encrypted content
all entries readable and scanned
None
Executable binaries
no .exe / .dll / .so / script binaries
None
Package
Theme header
Name
myPortfolio by MyThemeShop
Version
1.3.10
Version check
Match
package and product page both state 1.3.10
Author
MyThemeShop
Author URI
http://mythemeshop.com
Project URI
http://mythemeshop.com/themes/myportfolio
Description
myPortfolio is a stunning, responsive and highly modern WordPress theme that is perfectly suited to businesses that want to showcase their services and products.
Individual filenames are withheld. Each entry shows its type, its folder within the package and its own SHA-256.
PNG · options/child-theme
58a8e318d5c9c80a…
843.4 KB
PNG · package root
58a8e318d5c9c80a…
843.4 KB
XML · options/demo-importer/demo-files/blog
5dbb6b6f8a25b7bd…
829.7 KB
XML · options/demo-importer/demo-files/default
cc6ad1ca47c97124…
829.7 KB
SVG · fonts
ad6157926c1622ba…
434.0 KB
PEM · functions
238823cd92d3bcdd…
208.9 KB
PHP · functions
e5cc2f9b7ab9b2aa…
189.9 KB
EOT · fonts
7bfcab6db99d5cfb…
161.9 KB
Code signals
5 present
Observations, not findings. Every construct below appears in ordinary, legitimate plugins — they are listed so you can judge for yourself. Only ClamAV decides this package's verdict.
unserialize
Unsafe when given untrusted input
Deserialization4
eval (JavaScript)
Executes a string as code
Code execution1
file_get_contents(url)
Fetches a remote URL
Remote request1
base64_decode
Decodes base64 — routine, but also how packed code hides
Obfuscation1
curl_exec
Makes an outbound HTTP request
Remote request1
Referenced hosts
20 distinct
Domains appearing in the package source. Most are documentation links or CDNs; their presence is not evidence the package contacts them.