Individual filenames are withheld. Each entry shows its type, its folder within the package and its own SHA-256.
POT · languages
8f7a840ee73ad013…
1.08 MB
PO · languages
e438b6203765d929…
707.4 KB
JS · assets/lib/fullcalendar
4b6c3ffbd9825887…
683.4 KB
JS · assets/lib/three-vanta
74782bdbcf6518f7…
601.2 KB
JS · assets/lib/fullcalendar
223ff800a0b0b87a…
277.3 KB
PHP · modules/posts/skins
cb1e35efd9ddac6c…
234.6 KB
JS · assets/lib/chartjs
2f27bcf471b2d69d…
203.5 KB
PO · languages
f9885ff13592a55d…
182.1 KB
Code signals
4 present
Observations, not findings. Every construct below appears in ordinary, legitimate plugins — they are listed so you can judge for yourself. Only ClamAV decides this package's verdict.
unserialize
Unsafe when given untrusted input
Deserialization3
eval (JavaScript)
Executes a string as code
Code execution2
curl_exec
Makes an outbound HTTP request
Remote request1
file_get_contents(url)
Fetches a remote URL
Remote request1
Referenced hosts
20 distinct
Domains appearing in the package source. Most are documentation links or CDNs; their presence is not evidence the package contacts them.