WooCommerce Smart Coupons · Sep 07, 2026, 08:16 AM UTC
Cleanzip289 entriescrc-verifiedphpjavascriptcss
ZIP
3.69 MB
package size
Analysis
6 checks · 0 flagged
ClamAV 1.5.4 signature scan
3,628,051 signatures · db v28115
Undetected
ClamAV PUA heuristics
no unwanted applications
Undetected
Archive integrity
CRC verified for every entry
Valid
Path traversal (Zip Slip)
no entry escapes the extraction directory
Undetected
Encrypted content
all entries readable and scanned
None
Executable binaries
no .exe / .dll / .so / script binaries
None
Package
Plugin header
Name
WooCommerce Smart Coupons
Version
9.82.0
Version check
Match
package and product page both state 9.82.0
Author
StoreApps
Author URI
https://www.storeapps.org
Project URI
https://woocommerce.com/products/smart-coupons
Description
<strong>WooCommerce Smart Coupons</strong> lets customers buy gift certificates, store credits or coupons easily. They can use purchased credits themselves or gift to someone else.
Individual filenames are withheld. Each entry shows its type, its folder within the package and its own SHA-256.
PNG · assets/images
6e55f32b55986ffa…
694.2 KB
PHP · includes
eaa1b2ed0ce9c3d8…
369.7 KB
PO · languages
5fbd707d1c6c205d…
292.8 KB
PO · languages
a65aa56f78bc51e6…
286.3 KB
PO · languages
01e5c08d8207a490…
278.7 KB
PO · languages
b297685ae29be0b6…
264.4 KB
PO · languages
1a4d705dd6fb3997…
262.9 KB
PO · languages
9ce73c1d5a42725d…
261.9 KB
Code signals
3 present
Observations, not findings. Every construct below appears in ordinary, legitimate plugins — they are listed so you can judge for yourself. Only ClamAV decides this package's verdict.
eval (JavaScript)
Executes a string as code
Code execution2
unserialize
Unsafe when given untrusted input
Deserialization2
base64_decode
Decodes base64 — routine, but also how packed code hides
Obfuscation1
Referenced hosts
9 distinct
Domains appearing in the package source. Most are documentation links or CDNs; their presence is not evidence the package contacts them.