The <code><strong>YITH WooCommerce Waitlist</strong></code> plugin allows your customers to request an email notification when an out-of-stock product comes back into stock. <a href="https://yithemes.com/" target="_blank">Get more plugins for your e-commerce shop on <strong>YITH</strong></a>.
Individual filenames are withheld. Each entry shows its type, its folder within the package and its own SHA-256.
JS · node_modules/sass
…
5.17 MB
JS · node_modules/terser/dist
66281950d473e2c6…
1.00 MB
JS · node_modules/lodash
4c04561befdf653a…
531.3 KB
SVG · plugin-fw/assets/fonts/font-awesome
ad6157926c1622ba…
434.0 KB
NODE · node_modules/@parcel/watcher-darwin-arm64
ea31618e251be57f…
334.6 KB
O · node_modules/cpu-features/build/Release/obj.target/cpufeatures/src
4cfdefe5e23f531e…
328.4 KB
JS · node_modules/esprima/dist
6c36c0e60387f539…
276.9 KB
MAP · node_modules/axios/dist/node
ab5e363daf53af6b…
267.6 KB
Code signals
8 present
Observations, not findings. Every construct below appears in ordinary, legitimate plugins — they are listed so you can judge for yourself. Only ClamAV decides this package's verdict.
new Function()
Builds a function from a string
Code execution33
exec / system
Runs an operating-system command
System command10
eval (JavaScript)
Executes a string as code
Code execution7
curl_exec
Makes an outbound HTTP request
Remote request2
base64_decode
Decodes base64 — routine, but also how packed code hides
Obfuscation2
eval
Executes a string as code
Code execution2
atob
Decodes base64 in the browser
Obfuscation2
unserialize
Unsafe when given untrusted input
Deserialization1
Referenced hosts
20 distinct
Domains appearing in the package source. Most are documentation links or CDNs; their presence is not evidence the package contacts them.