Individual filenames are withheld. Each entry shows its type, its folder within the package and its own SHA-256.
JS · js/ace-min-noconflict
32bd4f7210753816…
338.0 KB
JS · js/ace-min-noconflict
695ee867a4e290e9…
212.3 KB
JS · js/ace-min-noconflict
0d3326ee88fe474b…
163.6 KB
JS · js/ace-min-noconflict
49a146c4900565cd…
155.0 KB
JS · js/ace-min-noconflict
19db8b1441927110…
137.4 KB
JS · js/ace-min-noconflict
0332858fbbcd952a…
133.8 KB
PHP · inc/scssphp
81c958f4c134b630…
111.4 KB
PHP · package root
cb91d3311bd29ea1…
90.0 KB
Code signals
5 present
Observations, not findings. Every construct below appears in ordinary, legitimate plugins — they are listed so you can judge for yourself. Only ClamAV decides this package's verdict.
unserialize
Unsafe when given untrusted input
Deserialization8
eval (JavaScript)
Executes a string as code
Code execution5
base64_decode
Decodes base64 — routine, but also how packed code hides
Obfuscation4
file_get_contents(url)
Fetches a remote URL
Remote request3
new Function()
Builds a function from a string
Code execution2
Referenced hosts
20 distinct
Domains appearing in the package source. Most are documentation links or CDNs; their presence is not evidence the package contacts them.