Individual filenames are withheld. Each entry shows its type, its folder within the package and its own SHA-256.
SVG · assets/fonts/font-awesome/fonts
8e3586389bb4cd01…
382.4 KB
JS · plugin-fw/assets/js/codemirror
dc6bec8d75a3c919…
221.2 KB
PNG · assets/images/devices
cf65289042ac83ab…
214.9 KB
PNG · assets/images/devices
f0edf7c728d3661a…
208.3 KB
JS · plugin-upgrade/assets/js/selectWoo
ef11268c75f63851…
163.8 KB
TTF · assets/fonts/font-awesome/fonts
ae19e2e4c04f2b04…
149.2 KB
JS · plugin-upgrade/assets/js/selectWoo
5f1bdc26d14320da…
144.4 KB
OTF · assets/fonts/font-awesome/fonts
ecd72f31910a8ee2…
122.1 KB
Code signals
2 present
Observations, not findings. Every construct below appears in ordinary, legitimate plugins — they are listed so you can judge for yourself. Only ClamAV decides this package's verdict.
unserialize
Unsafe when given untrusted input
Deserialization1
eval (JavaScript)
Executes a string as code
Code execution1
Referenced hosts
20 distinct
Domains appearing in the package source. Most are documentation links or CDNs; their presence is not evidence the package contacts them.