MyThemehop Authority WordPress Theme · Sep 10, 2026, 08:35 AM UTC
Cleanzip1447 entriescrc-verifiedpngphpjavascript
ZIP
5.37 MB
package size
Analysis
6 checks · 0 flagged
ClamAV 1.5.4 signature scan
3,628,051 signatures · db v28115
Undetected
ClamAV PUA heuristics
no unwanted applications
Undetected
Archive integrity
CRC verified for every entry
Valid
Path traversal (Zip Slip)
no entry escapes the extraction directory
Undetected
Encrypted content
all entries readable and scanned
None
Executable binaries
no .exe / .dll / .so / script binaries
None
Package
Theme header
Name
Authority by MyThemeShop
Version
1.2.11
Version check
Match
package and product page both state 1.2.11
Author
MyThemeShop
Author URI
http://mythemeshop.com
Project URI
http://mythemeshop.com/themes/authority
Description
Authority is a theme that’s styled after Matthew Woodward’s six figure blog. Benefit from the same features, optimization and customization and increase your trust and authority!
Individual filenames are withheld. Each entry shows its type, its folder within the package and its own SHA-256.
XML · options/demo-importer/demo-files/default
…
2.15 MB
XML · options/demo-importer/demo-files/tech
e0d48c349fc33325…
802.4 KB
XML · options/demo-importer/demo-files/travel
a426622e1ac8c638…
531.6 KB
SVG · fonts
ad6157926c1622ba…
434.0 KB
XML · options/demo-importer/demo-files/review
a69d6b73d42d3177…
391.0 KB
PNG · options/child-theme
6fe8c543d2256f04…
317.6 KB
PNG · package root
6fe8c543d2256f04…
317.6 KB
PEM · functions
238823cd92d3bcdd…
208.9 KB
Code signals
4 present
Observations, not findings. Every construct below appears in ordinary, legitimate plugins — they are listed so you can judge for yourself. Only ClamAV decides this package's verdict.
unserialize
Unsafe when given untrusted input
Deserialization4
file_get_contents(url)
Fetches a remote URL
Remote request1
base64_decode
Decodes base64 — routine, but also how packed code hides
Obfuscation1
curl_exec
Makes an outbound HTTP request
Remote request1
Referenced hosts
20 distinct
Domains appearing in the package source. Most are documentation links or CDNs; their presence is not evidence the package contacts them.