Individual filenames are withheld. Each entry shows its type, its folder within the package and its own SHA-256.
JS · assets/js
c4e6eeac6825e283…
821.6 KB
JSON · vendor/wp-media/plugin-family
9303c27561150a2b…
793.4 KB
JSON · vendor/wordpress/mcp-adapter
77899f188078e982…
726.6 KB
MAP · assets/js
c5e2b2efd152b13d…
580.9 KB
PO · languages
6a6c9cad77eec05d…
270.4 KB
LOCK · package root
e560df587f92744a…
245.7 KB
PO · languages
ff6b4308db373a0a…
245.5 KB
PO · languages
2ef568a07a7c92d9…
230.7 KB
Code signals
6 present
Observations, not findings. Every construct below appears in ordinary, legitimate plugins — they are listed so you can judge for yourself. Only ClamAV decides this package's verdict.
unserialize
Unsafe when given untrusted input
Deserialization4
base64_decode
Decodes base64 — routine, but also how packed code hides
Obfuscation4
assert
Can execute a string as code on old PHP
Code execution3
exec / system
Runs an operating-system command
System command2
new Function()
Builds a function from a string
Code execution1
gzinflate
Decompresses a string in memory
Obfuscation1
Referenced hosts
20 distinct
Domains appearing in the package source. Most are documentation links or CDNs; their presence is not evidence the package contacts them.