Individual filenames are withheld. Each entry shows its type, its folder within the package and its own SHA-256.
PHP · vendor/composer
c944c4b1228ef6be…
15.7 KB
PHP · classes
431ddf078603bfd9…
14.6 KB
PHP · classes
542d410d67d831e5…
7.4 KB
PHP · includes/Product
ada3ac7da17b9c5c…
6.9 KB
PHP · vendor/composer
c3ebbae193d160eb…
6.1 KB
PHP · includes/PROInstall
85a0acc0a8e6714a…
5.3 KB
JS · assets/js
8a40cc3a47fd1384…
4.2 KB
PHP · includes
770cfe4f00248b9e…
4.2 KB
Code signals
1 present
Observations, not findings. Every construct below appears in ordinary, legitimate plugins — they are listed so you can judge for yourself. Only ClamAV decides this package's verdict.
unserialize
Unsafe when given untrusted input
Deserialization1
Referenced hosts
6 distinct
Domains appearing in the package source. Most are documentation links or CDNs; their presence is not evidence the package contacts them.