Individual filenames are withheld. Each entry shows its type, its folder within the package and its own SHA-256.
TTF · views/vendor_invoice/fonts
7da195a74c55bef9…
739.3 KB
JS · assets/js/wc_fncy_product_designer
8308e326da9d62ef…
695.4 KB
TTF · views/vendor_invoice/fonts
e6476c1b80502924…
689.1 KB
JS · assets/js/wc_fncy_product_designer
a31c8a43921ea799…
676.7 KB
WAV · includes/libs/firebase/sounds
5881639a43247504…
488.1 KB
WAV · includes/libs/firebase_admin_sdk/sounds
5881639a43247504…
488.1 KB
JS · assets/js/wc_fncy_product_designer
e1a62fd1c970551c…
369.3 KB
SVG · includes/libs/firebase/fonts
7414288c272f6cc1…
347.6 KB
Code signals
6 present
Observations, not findings. Every construct below appears in ordinary, legitimate plugins — they are listed so you can judge for yourself. Only ClamAV decides this package's verdict.
unserialize
Unsafe when given untrusted input
Deserialization11
base64_decode
Decodes base64 — routine, but also how packed code hides
Obfuscation10
curl_exec
Makes an outbound HTTP request
Remote request6
new Function()
Builds a function from a string
Code execution3
atob
Decodes base64 in the browser
Obfuscation3
eval (JavaScript)
Executes a string as code
Code execution2
Referenced hosts
20 distinct
Domains appearing in the package source. Most are documentation links or CDNs; their presence is not evidence the package contacts them.