Individual filenames are withheld. Each entry shows its type, its folder within the package and its own SHA-256.
JS · assets/fontawesome/js
19a7ab5f66bf0ee3…
1.20 MB
JS · assets/fontawesome/js
812ab0e46f86b2ce…
1.14 MB
JSON · includes/gutenberg
739ecc8a7b41be61…
992.2 KB
SVG · assets/fontawesome/webfonts
9674eb1bd5504717…
897.5 KB
JSON · package root
de1d25394dea4723…
781.3 KB
SVG · assets/fontawesome/webfonts
a3b9817780214caf…
730.4 KB
JS · assets/fontawesome/js
6ce9d76ae07c2b54…
605.8 KB
JS · assets/fontawesome/js
877f5ef789807740…
593.1 KB
Code signals
2 present
Observations, not findings. Every construct below appears in ordinary, legitimate plugins — they are listed so you can judge for yourself. Only ClamAV decides this package's verdict.
unserialize
Unsafe when given untrusted input
Deserialization2
base64_decode
Decodes base64 — routine, but also how packed code hides
Obfuscation1
Referenced hosts
20 distinct
Domains appearing in the package source. Most are documentation links or CDNs; their presence is not evidence the package contacts them.