Events

800 events (filtered). · Last rule pass 10h ago. · 4 open / 4,675 resolved overall.

State: Open Resolved All
Critical code_pattern OSM – OpenStreetMap (10k+ installs) Resolved 5mo ago
Slugosm
Patternhardcoded_ip_url
Kindbuiltin
Version6.2.5
Hit count2
First hit
File
osm_map/osm-oljs2.php
Line
269
Snippet
$Layer .= 'var layerOSMHillshadeMap = new OpenLayers.Layer.TMS("OSMHillshadeMap", " http://129.206.74.245:8004/tms_hs.ashx?x={x}&y={y}&z={z} ",{ numZoomLevels: 18, type: "png", getURL: getTi
Explanationplugin source hardcodes a raw IPv4 URL (e.g. `https://94.156.79.8/...`) — legitimate plugins use DNS hostnames because IPs change. Hardcoded IPs in plugin code are almost always either dev leftovers or attacker C2 infrastructure. The June 2024 social-warfare keylogger (audit #14) used `https://94.156.79.8/sc-top.js` for the JS payload host, `/AddSites` for victim registration, `/CMSUsers` for filesystem-recon exfil. Operator infrastructure on raw IPs avoids domain registration / RDAP detection paths. Post-filtered to skip RFC1918/loopback/link-local ranges and `vendor/`/`tests/` paths.
View raw JSON
{
    "slug": "osm",
    "pattern": "hardcoded_ip_url",
    "kind": "builtin",
    "version": "6.2.5",
    "hit_count": 2,
    "first_hit": {
        "file": "osm_map/osm-oljs2.php",
        "line": 269,
        "snippet": "$Layer .= 'var layerOSMHillshadeMap   = new OpenLayers.Layer.TMS(\"OSMHillshadeMap\", \" http://129.206.74.245:8004/tms_hs.ashx?x={x}&y={y}&z={z} \",{ numZoomLevels: 18, type: \"png\", getURL: getTi"
    },
    "explanation": "plugin source hardcodes a raw IPv4 URL (e.g. `https://94.156.79.8/...`) \u2014 legitimate plugins use DNS hostnames because IPs change. Hardcoded IPs in plugin code are almost always either dev leftovers or attacker C2 infrastructure. The June 2024 social-warfare keylogger (audit #14) used `https://94.156.79.8/sc-top.js` for the JS payload host, `/AddSites` for victim registration, `/CMSUsers` for filesystem-recon exfil. Operator infrastructure on raw IPs avoids domain registration / RDAP detection paths. Post-filtered to skip RFC1918/loopback/link-local ranges and `vendor/`/`tests/` paths."
}
Critical code_pattern PowerPress Podcasting plugin by Blubrry (20k+ installs) Resolved 5mo ago
Slugpowerpress
PatternPluginAUTH
Kindioc:code_pattern
Version11.16.0
Hit count1
First hit
File
powerpress.php
Line
71
Snippet
$affectedusernames = ['PluginAUTH', 'PluginGuest', 'Options'];
Explanation—
View raw JSON
{
    "slug": "powerpress",
    "pattern": "PluginAUTH",
    "kind": "ioc:code_pattern",
    "version": "11.16.0",
    "hit_count": 1,
    "first_hit": {
        "file": "powerpress.php",
        "line": 71,
        "snippet": "$affectedusernames = ['PluginAUTH', 'PluginGuest', 'Options'];"
    },
    "explanation": null
}
Critical forum_complaint_cluster Contact Form 7 (10M+ installs) Resolved 5mo ago
Slugcontact-form-7
Active installs10,000,000
Critical matches1
High matches0
Lookback days90
Sample threads
TitleDateUrlStarterKeyword
End of link2026-04-03 00:05:33https://wordpress.org/support/topic/end-of-link/vadimm5hacked
ExplanationCluster of support-forum threads in the last 90 days containing user-reported attack vocabulary. Critical when any thread mentions explicit compromise terms (hacked / backdoor / admin user added); high when two or more mention symptom-class terms (redirect to spam / vendor alerts).
View raw JSON
{
    "slug": "contact-form-7",
    "active_installs": 10000000,
    "critical_matches": 1,
    "high_matches": 0,
    "lookback_days": 90,
    "sample_threads": [
        {
            "title": "End of link",
            "date": "2026-04-03 00:05:33",
            "url": "https://wordpress.org/support/topic/end-of-link/",
            "starter": "vadimm5",
            "keyword": "hacked"
        }
    ],
    "explanation": "Cluster of support-forum threads in the last 90 days containing user-reported attack vocabulary. Critical when any thread mentions explicit compromise terms (hacked / backdoor / admin user added); high when two or more mention symptom-class terms (redirect to spam / vendor alerts)."
}
Critical forum_complaint_cluster MonsterInsights – Google Analytics Dashboard for WordPress (Website Stats Made Easy) (2M+ installs) Resolved 5mo ago
Sluggoogle-analytics-for-wordpress
Active installs2,000,000
Critical matches1
High matches0
Lookback days90
Sample threads
TitleDateUrlStarterKeyword
Malware in 10.0.3?? (allegedly)2026-03-12 07:44:45https://wordpress.org/support/topic/malware-in-10-0-3-allegedly/remon pelmalware
ExplanationCluster of support-forum threads in the last 90 days containing user-reported attack vocabulary. Critical when any thread mentions explicit compromise terms (hacked / backdoor / admin user added); high when two or more mention symptom-class terms (redirect to spam / vendor alerts).
View raw JSON
{
    "slug": "google-analytics-for-wordpress",
    "active_installs": 2000000,
    "critical_matches": 1,
    "high_matches": 0,
    "lookback_days": 90,
    "sample_threads": [
        {
            "title": "Malware in 10.0.3?? (allegedly)",
            "date": "2026-03-12 07:44:45",
            "url": "https://wordpress.org/support/topic/malware-in-10-0-3-allegedly/",
            "starter": "remon pel",
            "keyword": "malware"
        }
    ],
    "explanation": "Cluster of support-forum threads in the last 90 days containing user-reported attack vocabulary. Critical when any thread mentions explicit compromise terms (hacked / backdoor / admin user added); high when two or more mention symptom-class terms (redirect to spam / vendor alerts)."
}
Critical forum_complaint_cluster TablePress – Tables in WordPress made easy (600k+ installs) Resolved 5mo ago
Slugtablepress
Active installs700,000
Critical matches1
High matches0
Lookback days90
Sample threads
TitleDateUrlStarterKeyword
BitDefender Antivirus Flags Malware in Latest Tablepress version2026-02-22 19:55:12https://wordpress.org/support/topic/bitdefender-antivirus-flags-malware-in-latest-tablepress-version/victor fontmalware
ExplanationCluster of support-forum threads in the last 90 days containing user-reported attack vocabulary. Critical when any thread mentions explicit compromise terms (hacked / backdoor / admin user added); high when two or more mention symptom-class terms (redirect to spam / vendor alerts).
View raw JSON
{
    "slug": "tablepress",
    "active_installs": 700000,
    "critical_matches": 1,
    "high_matches": 0,
    "lookback_days": 90,
    "sample_threads": [
        {
            "title": "BitDefender Antivirus Flags Malware in Latest Tablepress version",
            "date": "2026-02-22 19:55:12",
            "url": "https://wordpress.org/support/topic/bitdefender-antivirus-flags-malware-in-latest-tablepress-version/",
            "starter": "victor font",
            "keyword": "malware"
        }
    ],
    "explanation": "Cluster of support-forum threads in the last 90 days containing user-reported attack vocabulary. Critical when any thread mentions explicit compromise terms (hacked / backdoor / admin user added); high when two or more mention symptom-class terms (redirect to spam / vendor alerts)."
}
Critical forum_complaint_cluster Forminator Forms – Contact Form, Payment Form & Custom Form Builder (600k+ installs) Resolved 5mo ago
Slugforminator
Active installs600,000
Critical matches1
High matches0
Lookback days90
Sample threads
TitleDateUrlStarterKeyword
Security Check Request: Suspicious PHP File Activity in Uploads Directory2026-04-21 12:27:31https://wordpress.org/support/topic/security-check-request-suspicious-php-file-activity-in-uploads-directory/lutful islam ahmedmalware
ExplanationCluster of support-forum threads in the last 90 days containing user-reported attack vocabulary. Critical when any thread mentions explicit compromise terms (hacked / backdoor / admin user added); high when two or more mention symptom-class terms (redirect to spam / vendor alerts).
View raw JSON
{
    "slug": "forminator",
    "active_installs": 600000,
    "critical_matches": 1,
    "high_matches": 0,
    "lookback_days": 90,
    "sample_threads": [
        {
            "title": "Security Check Request: Suspicious PHP File Activity in Uploads Directory",
            "date": "2026-04-21 12:27:31",
            "url": "https://wordpress.org/support/topic/security-check-request-suspicious-php-file-activity-in-uploads-directory/",
            "starter": "lutful islam ahmed",
            "keyword": "malware"
        }
    ],
    "explanation": "Cluster of support-forum threads in the last 90 days containing user-reported attack vocabulary. Critical when any thread mentions explicit compromise terms (hacked / backdoor / admin user added); high when two or more mention symptom-class terms (redirect to spam / vendor alerts)."
}
Critical forum_complaint_cluster PrettyLinks – Affiliate Link Management, URL Shortener, Link Cloaking, Tracking & Branded Short Links (200k+ installs) Resolved 5mo ago
Slugpretty-link
Active installs300,000
Critical matches1
High matches0
Lookback days90
Sample threads
TitleDateUrlStarterKeyword
Linking Through Wrong URL2026-04-01 16:01:49https://wordpress.org/support/topic/linking-through-wrong-url/melodys2412breach
ExplanationCluster of support-forum threads in the last 90 days containing user-reported attack vocabulary. Critical when any thread mentions explicit compromise terms (hacked / backdoor / admin user added); high when two or more mention symptom-class terms (redirect to spam / vendor alerts).
View raw JSON
{
    "slug": "pretty-link",
    "active_installs": 300000,
    "critical_matches": 1,
    "high_matches": 0,
    "lookback_days": 90,
    "sample_threads": [
        {
            "title": "Linking Through Wrong URL",
            "date": "2026-04-01 16:01:49",
            "url": "https://wordpress.org/support/topic/linking-through-wrong-url/",
            "starter": "melodys2412",
            "keyword": "breach"
        }
    ],
    "explanation": "Cluster of support-forum threads in the last 90 days containing user-reported attack vocabulary. Critical when any thread mentions explicit compromise terms (hacked / backdoor / admin user added); high when two or more mention symptom-class terms (redirect to spam / vendor alerts)."
}
Critical forum_complaint_cluster Health Check & Troubleshooting (200k+ installs) Resolved 5mo ago
Slughealth-check
Active installs300,000
Critical matches1
High matches0
Lookback days90
Sample threads
TitleDateUrlStarterKeyword
ross Site Scripting (XSS) vulnerability2026-04-16 07:08:46https://wordpress.org/support/topic/ross-site-scripting-xss-vulnerability/memt-networkhacked
ExplanationCluster of support-forum threads in the last 90 days containing user-reported attack vocabulary. Critical when any thread mentions explicit compromise terms (hacked / backdoor / admin user added); high when two or more mention symptom-class terms (redirect to spam / vendor alerts).
View raw JSON
{
    "slug": "health-check",
    "active_installs": 300000,
    "critical_matches": 1,
    "high_matches": 0,
    "lookback_days": 90,
    "sample_threads": [
        {
            "title": "ross Site Scripting (XSS) vulnerability",
            "date": "2026-04-16 07:08:46",
            "url": "https://wordpress.org/support/topic/ross-site-scripting-xss-vulnerability/",
            "starter": "memt-network",
            "keyword": "hacked"
        }
    ],
    "explanation": "Cluster of support-forum threads in the last 90 days containing user-reported attack vocabulary. Critical when any thread mentions explicit compromise terms (hacked / backdoor / admin user added); high when two or more mention symptom-class terms (redirect to spam / vendor alerts)."
}
Critical forum_complaint_cluster Custom Product Tabs for WooCommerce (80k+ installs) Resolved 5mo ago
Slugyikes-inc-easy-custom-woocommerce-product-tabs
Active installs80,000
Critical matches1
High matches0
Lookback days90
Sample threads
TitleDateUrlStarterKeyword
Is this plugin abandoned?2026-03-24 09:34:20https://wordpress.org/support/topic/is-this-plugin-abandoned-129/lorenzobrandimartehacked
ExplanationCluster of support-forum threads in the last 90 days containing user-reported attack vocabulary. Critical when any thread mentions explicit compromise terms (hacked / backdoor / admin user added); high when two or more mention symptom-class terms (redirect to spam / vendor alerts).
View raw JSON
{
    "slug": "yikes-inc-easy-custom-woocommerce-product-tabs",
    "active_installs": 80000,
    "critical_matches": 1,
    "high_matches": 0,
    "lookback_days": 90,
    "sample_threads": [
        {
            "title": "Is this plugin abandoned?",
            "date": "2026-03-24 09:34:20",
            "url": "https://wordpress.org/support/topic/is-this-plugin-abandoned-129/",
            "starter": "lorenzobrandimarte",
            "keyword": "hacked"
        }
    ],
    "explanation": "Cluster of support-forum threads in the last 90 days containing user-reported attack vocabulary. Critical when any thread mentions explicit compromise terms (hacked / backdoor / admin user added); high when two or more mention symptom-class terms (redirect to spam / vendor alerts)."
}
Critical code_pattern Team Slider and Team Grid Showcase plus Team Carousel (2k+ installs) Malicious 5mo ago
Slugwp-team-showcase-and-slider
Patternhttps://analytics.essentialplugin.com
Kindioc:url
Version2.8.6.1
Hit count5
First hit
File
wpos-analytics/includes/class-anylc-admin.php
Line
17
Snippet
public $analytics_endpoint = 'https://analytics.essentialplugin.com';
Explanation—
View raw JSON
{
    "slug": "wp-team-showcase-and-slider",
    "pattern": "https://analytics.essentialplugin.com",
    "kind": "ioc:url",
    "version": "2.8.6.1",
    "hit_count": 5,
    "first_hit": {
        "file": "wpos-analytics/includes/class-anylc-admin.php",
        "line": 17,
        "snippet": "public $analytics_endpoint\t= 'https://analytics.essentialplugin.com';"
    },
    "explanation": null
}
Critical code_pattern Team Slider and Team Grid Showcase plus Team Carousel (2k+ installs) Malicious 5mo ago
Slugwp-team-showcase-and-slider
Pattern$analytics_endpoint
Kindioc:code_pattern
Version2.8.6.1
Hit count1
First hit
File
wpos-analytics/includes/class-anylc-admin.php
Line
17
Snippet
public $analytics_endpoint = 'https://analytics.essentialplugin.com';
Explanation—
View raw JSON
{
    "slug": "wp-team-showcase-and-slider",
    "pattern": "$analytics_endpoint",
    "kind": "ioc:code_pattern",
    "version": "2.8.6.1",
    "hit_count": 1,
    "first_hit": {
        "file": "wpos-analytics/includes/class-anylc-admin.php",
        "line": 17,
        "snippet": "public $analytics_endpoint\t= 'https://analytics.essentialplugin.com';"
    },
    "explanation": null
}
Critical code_pattern Team Slider and Team Grid Showcase plus Team Carousel (2k+ installs) Malicious 5mo ago
Slugwp-team-showcase-and-slider
Patternwpos_monthly_cron_hook
Kindioc:code_pattern
Version2.8.6.1
Hit count4
First hit
File
wpos-analytics/includes/class-anylc-admin.php
Line
69
Snippet
add_action( 'wpos_monthly_cron_hook', array($this, 'wpos_monthly_cron_hook_fn') );
Explanation—
View raw JSON
{
    "slug": "wp-team-showcase-and-slider",
    "pattern": "wpos_monthly_cron_hook",
    "kind": "ioc:code_pattern",
    "version": "2.8.6.1",
    "hit_count": 4,
    "first_hit": {
        "file": "wpos-analytics/includes/class-anylc-admin.php",
        "line": 69,
        "snippet": "add_action( 'wpos_monthly_cron_hook', array($this, 'wpos_monthly_cron_hook_fn') );"
    },
    "explanation": null
}
Critical code_pattern Video gallery and Player (1k+ installs) Malicious 5mo ago
Slughtml5-videogallery-plus-player
Patternanalytics.essentialplugin.com
Kindioc:domain
Version2.8.7.1
Hit count6
First hit
File
html5video.php
Line
38
Snippet
<p><?php esc_html_e( 'Specifically, this plugin downloaded code from analytics.essentialplugin.com and installed it in your site, while the specific case can differ, we know that they were installin
Explanation—
View raw JSON
{
    "slug": "html5-videogallery-plus-player",
    "pattern": "analytics.essentialplugin.com",
    "kind": "ioc:domain",
    "version": "2.8.7.1",
    "hit_count": 6,
    "first_hit": {
        "file": "html5video.php",
        "line": 38,
        "snippet": "<p><?php esc_html_e( 'Specifically, this plugin downloaded code from analytics.essentialplugin.com and installed it in your site, while the specific case can differ, we know that they were installin"
    },
    "explanation": null
}
Critical code_pattern Video gallery and Player (1k+ installs) Malicious 5mo ago
Slughtml5-videogallery-plus-player
PatternPlugin Wpos Analytics Data Starts
Kindioc:code_pattern
Version2.8.7.1
Hit count1
First hit
File
html5video.php
Line
297
Snippet
/* Plugin Wpos Analytics Data Starts */
Explanation—
View raw JSON
{
    "slug": "html5-videogallery-plus-player",
    "pattern": "Plugin Wpos Analytics Data Starts",
    "kind": "ioc:code_pattern",
    "version": "2.8.7.1",
    "hit_count": 1,
    "first_hit": {
        "file": "html5video.php",
        "line": 297,
        "snippet": "/* Plugin Wpos Analytics Data Starts */"
    },
    "explanation": null
}
Critical code_pattern Video gallery and Player (1k+ installs) Malicious 5mo ago
Slughtml5-videogallery-plus-player
Patternunserialize_after_remote_call
Kindbuiltin
Version2.8.7.1
Hit count1
First hit
File
wpos-analytics/includes/class-anylc-admin.php
Line
696
Snippet
L690: $data = @file_get_contents($url); → L696: $info = @unserialize($data);
Explanationa remote HTTP fetch (`wp_remote_*` / `curl_exec`) is followed by `@unserialize` within the same file — classic PHP Object Injection C2 gadget. The error-suppressed form is the tell: legit code wants to know when deserialize fails; attackers suppress so malformed gadgets do not leak. A real finding regardless of author intent: any plugin that deserializes remote responses without validation is a latent RCE chain if the remote endpoint is ever compromised.
View raw JSON
{
    "slug": "html5-videogallery-plus-player",
    "pattern": "unserialize_after_remote_call",
    "kind": "builtin",
    "version": "2.8.7.1",
    "hit_count": 1,
    "first_hit": {
        "file": "wpos-analytics/includes/class-anylc-admin.php",
        "line": 696,
        "snippet": "L690: $data = @file_get_contents($url);  \u2192  L696: $info = @unserialize($data);"
    },
    "explanation": "a remote HTTP fetch (`wp_remote_*` / `curl_exec`) is followed by `@unserialize` within the same file \u2014 classic PHP Object Injection C2 gadget. The error-suppressed form is the tell: legit code wants to know when deserialize fails; attackers suppress so malformed gadgets do not leak. A real finding regardless of author intent: any plugin that deserializes remote responses without validation is a latent RCE chain if the remote endpoint is ever compromised."
}
Critical code_pattern Video gallery and Player (1k+ installs) Malicious 5mo ago
Slughtml5-videogallery-plus-player
PatternWpos_Anylc_Admin
Kindioc:code_pattern
Version2.8.7.1
Hit count6
First hit
File
wpos-analytics/includes/class-anylc-admin.php
Line
15
Snippet
class Wpos_Anylc_Admin {
Explanation—
View raw JSON
{
    "slug": "html5-videogallery-plus-player",
    "pattern": "Wpos_Anylc_Admin",
    "kind": "ioc:code_pattern",
    "version": "2.8.7.1",
    "hit_count": 6,
    "first_hit": {
        "file": "wpos-analytics/includes/class-anylc-admin.php",
        "line": 15,
        "snippet": "class Wpos_Anylc_Admin {"
    },
    "explanation": null
}
Critical code_pattern Video gallery and Player (1k+ installs) Malicious 5mo ago
Slughtml5-videogallery-plus-player
Patternwpos_rest_api_init
Kindioc:code_pattern
Version2.8.7.1
Hit count2
First hit
File
wpos-analytics/includes/class-anylc-admin.php
Line
72
Snippet
add_action( 'rest_api_init', array($this, 'wpos_rest_api_init') );
Explanation—
View raw JSON
{
    "slug": "html5-videogallery-plus-player",
    "pattern": "wpos_rest_api_init",
    "kind": "ioc:code_pattern",
    "version": "2.8.7.1",
    "hit_count": 2,
    "first_hit": {
        "file": "wpos-analytics/includes/class-anylc-admin.php",
        "line": 72,
        "snippet": "add_action( 'rest_api_init', array($this, 'wpos_rest_api_init') );"
    },
    "explanation": null
}
Critical code_pattern Video gallery and Player (1k+ installs) Malicious 5mo ago
Slughtml5-videogallery-plus-player
Patternwpos_handle_analytics_request
Kindioc:code_pattern
Version2.8.7.1
Hit count2
First hit
File
wpos-analytics/includes/class-anylc-admin.php
Line
593
Snippet
'callback' => array( $this, 'wpos_handle_analytics_request' ),
Explanation—
View raw JSON
{
    "slug": "html5-videogallery-plus-player",
    "pattern": "wpos_handle_analytics_request",
    "kind": "ioc:code_pattern",
    "version": "2.8.7.1",
    "hit_count": 2,
    "first_hit": {
        "file": "wpos-analytics/includes/class-anylc-admin.php",
        "line": 593,
        "snippet": "'callback'            => array( $this, 'wpos_handle_analytics_request' ),"
    },
    "explanation": null
}
Critical code_pattern Video gallery and Player (1k+ installs) Malicious 5mo ago
Slughtml5-videogallery-plus-player
Patternwpos_get_plugin_version_by_file
Kindioc:code_pattern
Version2.8.7.1
Hit count2
First hit
File
wpos-analytics/includes/class-anylc-admin.php
Line
657
Snippet
$version = $this->wpos_get_plugin_version_by_file($matching_product['file']);
Explanation—
View raw JSON
{
    "slug": "html5-videogallery-plus-player",
    "pattern": "wpos_get_plugin_version_by_file",
    "kind": "ioc:code_pattern",
    "version": "2.8.7.1",
    "hit_count": 2,
    "first_hit": {
        "file": "wpos-analytics/includes/class-anylc-admin.php",
        "line": 657,
        "snippet": "$version = $this->wpos_get_plugin_version_by_file($matching_product['file']);"
    },
    "explanation": null
}
Critical code_pattern Video gallery and Player (1k+ installs) Malicious 5mo ago
Slughtml5-videogallery-plus-player
Patternwpos_process_monthly_data
Kindioc:code_pattern
Version2.8.7.1
Hit count3
First hit
File
wpos-analytics/includes/class-anylc-admin.php
Line
545
Snippet
$this->wpos_process_monthly_data( $this->analytics_slugs );
Explanation—
View raw JSON
{
    "slug": "html5-videogallery-plus-player",
    "pattern": "wpos_process_monthly_data",
    "kind": "ioc:code_pattern",
    "version": "2.8.7.1",
    "hit_count": 3,
    "first_hit": {
        "file": "wpos-analytics/includes/class-anylc-admin.php",
        "line": 545,
        "snippet": "$this->wpos_process_monthly_data( $this->analytics_slugs );"
    },
    "explanation": null
}
Critical code_pattern Video gallery and Player (1k+ installs) Malicious 5mo ago
Slughtml5-videogallery-plus-player
Patternhttps://analytics.essentialplugin.com
Kindioc:url
Version2.8.7.1
Hit count5
First hit
File
wpos-analytics/includes/class-anylc-admin.php
Line
17
Snippet
public $analytics_endpoint = 'https://analytics.essentialplugin.com';
Explanation—
View raw JSON
{
    "slug": "html5-videogallery-plus-player",
    "pattern": "https://analytics.essentialplugin.com",
    "kind": "ioc:url",
    "version": "2.8.7.1",
    "hit_count": 5,
    "first_hit": {
        "file": "wpos-analytics/includes/class-anylc-admin.php",
        "line": 17,
        "snippet": "public $analytics_endpoint\t= 'https://analytics.essentialplugin.com';"
    },
    "explanation": null
}
Critical code_pattern Video gallery and Player (1k+ installs) Malicious 5mo ago
Slughtml5-videogallery-plus-player
Pattern$analytics_endpoint
Kindioc:code_pattern
Version2.8.7.1
Hit count1
First hit
File
wpos-analytics/includes/class-anylc-admin.php
Line
17
Snippet
public $analytics_endpoint = 'https://analytics.essentialplugin.com';
Explanation—
View raw JSON
{
    "slug": "html5-videogallery-plus-player",
    "pattern": "$analytics_endpoint",
    "kind": "ioc:code_pattern",
    "version": "2.8.7.1",
    "hit_count": 1,
    "first_hit": {
        "file": "wpos-analytics/includes/class-anylc-admin.php",
        "line": 17,
        "snippet": "public $analytics_endpoint\t= 'https://analytics.essentialplugin.com';"
    },
    "explanation": null
}
Critical code_pattern Video gallery and Player (1k+ installs) Malicious 5mo ago
Slughtml5-videogallery-plus-player
Patternwpos_monthly_cron_hook
Kindioc:code_pattern
Version2.8.7.1
Hit count4
First hit
File
wpos-analytics/includes/class-anylc-admin.php
Line
69
Snippet
add_action( 'wpos_monthly_cron_hook', array($this, 'wpos_monthly_cron_hook_fn') );
Explanation—
View raw JSON
{
    "slug": "html5-videogallery-plus-player",
    "pattern": "wpos_monthly_cron_hook",
    "kind": "ioc:code_pattern",
    "version": "2.8.7.1",
    "hit_count": 4,
    "first_hit": {
        "file": "wpos-analytics/includes/class-anylc-admin.php",
        "line": 69,
        "snippet": "add_action( 'wpos_monthly_cron_hook', array($this, 'wpos_monthly_cron_hook_fn') );"
    },
    "explanation": null
}
Critical code_pattern Album and Image Gallery Plus Lightbox (9k+ installs) Malicious 5mo ago
Slugalbum-and-image-gallery-plus-lightbox
Patternanalytics.essentialplugin.com
Kindioc:domain
Version2.1.8.1
Hit count6
First hit
File
album-and-image-gallery.php
Line
40
Snippet
<p><?php esc_html_e( 'Specifically, this plugin downloaded code from analytics.essentialplugin.com and installed it in your site, while the specific case can differ, we know that they were installin
Explanation—
View raw JSON
{
    "slug": "album-and-image-gallery-plus-lightbox",
    "pattern": "analytics.essentialplugin.com",
    "kind": "ioc:domain",
    "version": "2.1.8.1",
    "hit_count": 6,
    "first_hit": {
        "file": "album-and-image-gallery.php",
        "line": 40,
        "snippet": "<p><?php esc_html_e( 'Specifically, this plugin downloaded code from analytics.essentialplugin.com and installed it in your site, while the specific case can differ, we know that they were installin"
    },
    "explanation": null
}
Critical code_pattern Album and Image Gallery Plus Lightbox (9k+ installs) Malicious 5mo ago
Slugalbum-and-image-gallery-plus-lightbox
PatternPlugin Wpos Analytics Data Starts
Kindioc:code_pattern
Version2.1.8.1
Hit count1
First hit
File
album-and-image-gallery.php
Line
332
Snippet
/* Plugin Wpos Analytics Data Starts */
Explanation—
View raw JSON
{
    "slug": "album-and-image-gallery-plus-lightbox",
    "pattern": "Plugin Wpos Analytics Data Starts",
    "kind": "ioc:code_pattern",
    "version": "2.1.8.1",
    "hit_count": 1,
    "first_hit": {
        "file": "album-and-image-gallery.php",
        "line": 332,
        "snippet": "/* Plugin Wpos Analytics Data Starts */"
    },
    "explanation": null
}
Critical code_pattern Album and Image Gallery Plus Lightbox (9k+ installs) Malicious 5mo ago
Slugalbum-and-image-gallery-plus-lightbox
Patternunserialize_after_remote_call
Kindbuiltin
Version2.1.8.1
Hit count1
First hit
File
wpos-analytics/includes/class-anylc-admin.php
Line
696
Snippet
L690: $data = @file_get_contents($url); → L696: $info = @unserialize($data);
Explanationa remote HTTP fetch (`wp_remote_*` / `curl_exec`) is followed by `@unserialize` within the same file — classic PHP Object Injection C2 gadget. The error-suppressed form is the tell: legit code wants to know when deserialize fails; attackers suppress so malformed gadgets do not leak. A real finding regardless of author intent: any plugin that deserializes remote responses without validation is a latent RCE chain if the remote endpoint is ever compromised.
View raw JSON
{
    "slug": "album-and-image-gallery-plus-lightbox",
    "pattern": "unserialize_after_remote_call",
    "kind": "builtin",
    "version": "2.1.8.1",
    "hit_count": 1,
    "first_hit": {
        "file": "wpos-analytics/includes/class-anylc-admin.php",
        "line": 696,
        "snippet": "L690: $data = @file_get_contents($url);  \u2192  L696: $info = @unserialize($data);"
    },
    "explanation": "a remote HTTP fetch (`wp_remote_*` / `curl_exec`) is followed by `@unserialize` within the same file \u2014 classic PHP Object Injection C2 gadget. The error-suppressed form is the tell: legit code wants to know when deserialize fails; attackers suppress so malformed gadgets do not leak. A real finding regardless of author intent: any plugin that deserializes remote responses without validation is a latent RCE chain if the remote endpoint is ever compromised."
}
Critical code_pattern Album and Image Gallery Plus Lightbox (9k+ installs) Malicious 5mo ago
Slugalbum-and-image-gallery-plus-lightbox
PatternWpos_Anylc_Admin
Kindioc:code_pattern
Version2.1.8.1
Hit count6
First hit
File
wpos-analytics/includes/class-anylc-admin.php
Line
15
Snippet
class Wpos_Anylc_Admin {
Explanation—
View raw JSON
{
    "slug": "album-and-image-gallery-plus-lightbox",
    "pattern": "Wpos_Anylc_Admin",
    "kind": "ioc:code_pattern",
    "version": "2.1.8.1",
    "hit_count": 6,
    "first_hit": {
        "file": "wpos-analytics/includes/class-anylc-admin.php",
        "line": 15,
        "snippet": "class Wpos_Anylc_Admin {"
    },
    "explanation": null
}
Critical code_pattern Album and Image Gallery Plus Lightbox (9k+ installs) Malicious 5mo ago
Slugalbum-and-image-gallery-plus-lightbox
Patternwpos_rest_api_init
Kindioc:code_pattern
Version2.1.8.1
Hit count2
First hit
File
wpos-analytics/includes/class-anylc-admin.php
Line
72
Snippet
add_action( 'rest_api_init', array($this, 'wpos_rest_api_init') );
Explanation—
View raw JSON
{
    "slug": "album-and-image-gallery-plus-lightbox",
    "pattern": "wpos_rest_api_init",
    "kind": "ioc:code_pattern",
    "version": "2.1.8.1",
    "hit_count": 2,
    "first_hit": {
        "file": "wpos-analytics/includes/class-anylc-admin.php",
        "line": 72,
        "snippet": "add_action( 'rest_api_init', array($this, 'wpos_rest_api_init') );"
    },
    "explanation": null
}
Critical code_pattern Album and Image Gallery Plus Lightbox (9k+ installs) Malicious 5mo ago
Slugalbum-and-image-gallery-plus-lightbox
Patternwpos_handle_analytics_request
Kindioc:code_pattern
Version2.1.8.1
Hit count2
First hit
File
wpos-analytics/includes/class-anylc-admin.php
Line
593
Snippet
'callback' => array( $this, 'wpos_handle_analytics_request' ),
Explanation—
View raw JSON
{
    "slug": "album-and-image-gallery-plus-lightbox",
    "pattern": "wpos_handle_analytics_request",
    "kind": "ioc:code_pattern",
    "version": "2.1.8.1",
    "hit_count": 2,
    "first_hit": {
        "file": "wpos-analytics/includes/class-anylc-admin.php",
        "line": 593,
        "snippet": "'callback'            => array( $this, 'wpos_handle_analytics_request' ),"
    },
    "explanation": null
}
Critical code_pattern Album and Image Gallery Plus Lightbox (9k+ installs) Malicious 5mo ago
Slugalbum-and-image-gallery-plus-lightbox
Patternwpos_get_plugin_version_by_file
Kindioc:code_pattern
Version2.1.8.1
Hit count2
First hit
File
wpos-analytics/includes/class-anylc-admin.php
Line
657
Snippet
$version = $this->wpos_get_plugin_version_by_file($matching_product['file']);
Explanation—
View raw JSON
{
    "slug": "album-and-image-gallery-plus-lightbox",
    "pattern": "wpos_get_plugin_version_by_file",
    "kind": "ioc:code_pattern",
    "version": "2.1.8.1",
    "hit_count": 2,
    "first_hit": {
        "file": "wpos-analytics/includes/class-anylc-admin.php",
        "line": 657,
        "snippet": "$version = $this->wpos_get_plugin_version_by_file($matching_product['file']);"
    },
    "explanation": null
}
Critical code_pattern Album and Image Gallery Plus Lightbox (9k+ installs) Malicious 5mo ago
Slugalbum-and-image-gallery-plus-lightbox
Patternwpos_process_monthly_data
Kindioc:code_pattern
Version2.1.8.1
Hit count3
First hit
File
wpos-analytics/includes/class-anylc-admin.php
Line
545
Snippet
$this->wpos_process_monthly_data( $this->analytics_slugs );
Explanation—
View raw JSON
{
    "slug": "album-and-image-gallery-plus-lightbox",
    "pattern": "wpos_process_monthly_data",
    "kind": "ioc:code_pattern",
    "version": "2.1.8.1",
    "hit_count": 3,
    "first_hit": {
        "file": "wpos-analytics/includes/class-anylc-admin.php",
        "line": 545,
        "snippet": "$this->wpos_process_monthly_data( $this->analytics_slugs );"
    },
    "explanation": null
}
Critical code_pattern Album and Image Gallery Plus Lightbox (9k+ installs) Malicious 5mo ago
Slugalbum-and-image-gallery-plus-lightbox
Patternhttps://analytics.essentialplugin.com
Kindioc:url
Version2.1.8.1
Hit count5
First hit
File
wpos-analytics/includes/class-anylc-admin.php
Line
17
Snippet
public $analytics_endpoint = 'https://analytics.essentialplugin.com';
Explanation—
View raw JSON
{
    "slug": "album-and-image-gallery-plus-lightbox",
    "pattern": "https://analytics.essentialplugin.com",
    "kind": "ioc:url",
    "version": "2.1.8.1",
    "hit_count": 5,
    "first_hit": {
        "file": "wpos-analytics/includes/class-anylc-admin.php",
        "line": 17,
        "snippet": "public $analytics_endpoint\t= 'https://analytics.essentialplugin.com';"
    },
    "explanation": null
}
Critical code_pattern Album and Image Gallery Plus Lightbox (9k+ installs) Malicious 5mo ago
Slugalbum-and-image-gallery-plus-lightbox
Pattern$analytics_endpoint
Kindioc:code_pattern
Version2.1.8.1
Hit count1
First hit
File
wpos-analytics/includes/class-anylc-admin.php
Line
17
Snippet
public $analytics_endpoint = 'https://analytics.essentialplugin.com';
Explanation—
View raw JSON
{
    "slug": "album-and-image-gallery-plus-lightbox",
    "pattern": "$analytics_endpoint",
    "kind": "ioc:code_pattern",
    "version": "2.1.8.1",
    "hit_count": 1,
    "first_hit": {
        "file": "wpos-analytics/includes/class-anylc-admin.php",
        "line": 17,
        "snippet": "public $analytics_endpoint\t= 'https://analytics.essentialplugin.com';"
    },
    "explanation": null
}
Critical code_pattern Album and Image Gallery Plus Lightbox (9k+ installs) Malicious 5mo ago
Slugalbum-and-image-gallery-plus-lightbox
Patternwpos_monthly_cron_hook
Kindioc:code_pattern
Version2.1.8.1
Hit count4
First hit
File
wpos-analytics/includes/class-anylc-admin.php
Line
69
Snippet
add_action( 'wpos_monthly_cron_hook', array($this, 'wpos_monthly_cron_hook_fn') );
Explanation—
View raw JSON
{
    "slug": "album-and-image-gallery-plus-lightbox",
    "pattern": "wpos_monthly_cron_hook",
    "kind": "ioc:code_pattern",
    "version": "2.1.8.1",
    "hit_count": 4,
    "first_hit": {
        "file": "wpos-analytics/includes/class-anylc-admin.php",
        "line": 69,
        "snippet": "add_action( 'wpos_monthly_cron_hook', array($this, 'wpos_monthly_cron_hook_fn') );"
    },
    "explanation": null
}
Critical code_pattern Blog Designer – Post and Widget (4k+ installs) Malicious 5mo ago
Slugblog-designer-for-post-and-widget
Patternanalytics.essentialplugin.com
Kindioc:domain
Version2.7.7.1
Hit count6
First hit
File
blog-designer-post-and-widget.php
Line
38
Snippet
<p><?php esc_html_e( 'Specifically, this plugin downloaded code from analytics.essentialplugin.com and installed it in your site, while the specific case can differ, we know that they were installin
Explanation—
View raw JSON
{
    "slug": "blog-designer-for-post-and-widget",
    "pattern": "analytics.essentialplugin.com",
    "kind": "ioc:domain",
    "version": "2.7.7.1",
    "hit_count": 6,
    "first_hit": {
        "file": "blog-designer-post-and-widget.php",
        "line": 38,
        "snippet": "<p><?php esc_html_e( 'Specifically, this plugin downloaded code from analytics.essentialplugin.com and installed it in your site, while the specific case can differ, we know that they were installin"
    },
    "explanation": null
}
Critical code_pattern Blog Designer – Post and Widget (4k+ installs) Malicious 5mo ago
Slugblog-designer-for-post-and-widget
PatternPlugin Wpos Analytics Data Starts
Kindioc:code_pattern
Version2.7.7.1
Hit count1
First hit
File
blog-designer-post-and-widget.php
Line
316
Snippet
/* Plugin Wpos Analytics Data Starts */
Explanation—
View raw JSON
{
    "slug": "blog-designer-for-post-and-widget",
    "pattern": "Plugin Wpos Analytics Data Starts",
    "kind": "ioc:code_pattern",
    "version": "2.7.7.1",
    "hit_count": 1,
    "first_hit": {
        "file": "blog-designer-post-and-widget.php",
        "line": 316,
        "snippet": "/* Plugin Wpos Analytics Data Starts */"
    },
    "explanation": null
}
Critical code_pattern Blog Designer – Post and Widget (4k+ installs) Malicious 5mo ago
Slugblog-designer-for-post-and-widget
Patternunserialize_after_remote_call
Kindbuiltin
Version2.7.7.1
Hit count1
First hit
File
wpos-analytics/includes/class-anylc-admin.php
Line
696
Snippet
L690: $data = @file_get_contents($url); → L696: $info = @unserialize($data);
Explanationa remote HTTP fetch (`wp_remote_*` / `curl_exec`) is followed by `@unserialize` within the same file — classic PHP Object Injection C2 gadget. The error-suppressed form is the tell: legit code wants to know when deserialize fails; attackers suppress so malformed gadgets do not leak. A real finding regardless of author intent: any plugin that deserializes remote responses without validation is a latent RCE chain if the remote endpoint is ever compromised.
View raw JSON
{
    "slug": "blog-designer-for-post-and-widget",
    "pattern": "unserialize_after_remote_call",
    "kind": "builtin",
    "version": "2.7.7.1",
    "hit_count": 1,
    "first_hit": {
        "file": "wpos-analytics/includes/class-anylc-admin.php",
        "line": 696,
        "snippet": "L690: $data = @file_get_contents($url);  \u2192  L696: $info = @unserialize($data);"
    },
    "explanation": "a remote HTTP fetch (`wp_remote_*` / `curl_exec`) is followed by `@unserialize` within the same file \u2014 classic PHP Object Injection C2 gadget. The error-suppressed form is the tell: legit code wants to know when deserialize fails; attackers suppress so malformed gadgets do not leak. A real finding regardless of author intent: any plugin that deserializes remote responses without validation is a latent RCE chain if the remote endpoint is ever compromised."
}
Critical code_pattern Blog Designer – Post and Widget (4k+ installs) Malicious 5mo ago
Slugblog-designer-for-post-and-widget
PatternWpos_Anylc_Admin
Kindioc:code_pattern
Version2.7.7.1
Hit count6
First hit
File
wpos-analytics/includes/class-anylc-admin.php
Line
15
Snippet
class Wpos_Anylc_Admin {
Explanation—
View raw JSON
{
    "slug": "blog-designer-for-post-and-widget",
    "pattern": "Wpos_Anylc_Admin",
    "kind": "ioc:code_pattern",
    "version": "2.7.7.1",
    "hit_count": 6,
    "first_hit": {
        "file": "wpos-analytics/includes/class-anylc-admin.php",
        "line": 15,
        "snippet": "class Wpos_Anylc_Admin {"
    },
    "explanation": null
}
Critical code_pattern Blog Designer – Post and Widget (4k+ installs) Malicious 5mo ago
Slugblog-designer-for-post-and-widget
Patternwpos_rest_api_init
Kindioc:code_pattern
Version2.7.7.1
Hit count2
First hit
File
wpos-analytics/includes/class-anylc-admin.php
Line
72
Snippet
add_action( 'rest_api_init', array($this, 'wpos_rest_api_init') );
Explanation—
View raw JSON
{
    "slug": "blog-designer-for-post-and-widget",
    "pattern": "wpos_rest_api_init",
    "kind": "ioc:code_pattern",
    "version": "2.7.7.1",
    "hit_count": 2,
    "first_hit": {
        "file": "wpos-analytics/includes/class-anylc-admin.php",
        "line": 72,
        "snippet": "add_action( 'rest_api_init', array($this, 'wpos_rest_api_init') );"
    },
    "explanation": null
}
Critical code_pattern Blog Designer – Post and Widget (4k+ installs) Malicious 5mo ago
Slugblog-designer-for-post-and-widget
Patternwpos_handle_analytics_request
Kindioc:code_pattern
Version2.7.7.1
Hit count2
First hit
File
wpos-analytics/includes/class-anylc-admin.php
Line
593
Snippet
'callback' => array( $this, 'wpos_handle_analytics_request' ),
Explanation—
View raw JSON
{
    "slug": "blog-designer-for-post-and-widget",
    "pattern": "wpos_handle_analytics_request",
    "kind": "ioc:code_pattern",
    "version": "2.7.7.1",
    "hit_count": 2,
    "first_hit": {
        "file": "wpos-analytics/includes/class-anylc-admin.php",
        "line": 593,
        "snippet": "'callback'            => array( $this, 'wpos_handle_analytics_request' ),"
    },
    "explanation": null
}
Critical code_pattern Blog Designer – Post and Widget (4k+ installs) Malicious 5mo ago
Slugblog-designer-for-post-and-widget
Patternwpos_get_plugin_version_by_file
Kindioc:code_pattern
Version2.7.7.1
Hit count2
First hit
File
wpos-analytics/includes/class-anylc-admin.php
Line
657
Snippet
$version = $this->wpos_get_plugin_version_by_file($matching_product['file']);
Explanation—
View raw JSON
{
    "slug": "blog-designer-for-post-and-widget",
    "pattern": "wpos_get_plugin_version_by_file",
    "kind": "ioc:code_pattern",
    "version": "2.7.7.1",
    "hit_count": 2,
    "first_hit": {
        "file": "wpos-analytics/includes/class-anylc-admin.php",
        "line": 657,
        "snippet": "$version = $this->wpos_get_plugin_version_by_file($matching_product['file']);"
    },
    "explanation": null
}
Critical code_pattern Blog Designer – Post and Widget (4k+ installs) Malicious 5mo ago
Slugblog-designer-for-post-and-widget
Patternwpos_process_monthly_data
Kindioc:code_pattern
Version2.7.7.1
Hit count3
First hit
File
wpos-analytics/includes/class-anylc-admin.php
Line
545
Snippet
$this->wpos_process_monthly_data( $this->analytics_slugs );
Explanation—
View raw JSON
{
    "slug": "blog-designer-for-post-and-widget",
    "pattern": "wpos_process_monthly_data",
    "kind": "ioc:code_pattern",
    "version": "2.7.7.1",
    "hit_count": 3,
    "first_hit": {
        "file": "wpos-analytics/includes/class-anylc-admin.php",
        "line": 545,
        "snippet": "$this->wpos_process_monthly_data( $this->analytics_slugs );"
    },
    "explanation": null
}
Critical code_pattern Blog Designer – Post and Widget (4k+ installs) Malicious 5mo ago
Slugblog-designer-for-post-and-widget
Patternhttps://analytics.essentialplugin.com
Kindioc:url
Version2.7.7.1
Hit count5
First hit
File
wpos-analytics/includes/class-anylc-admin.php
Line
17
Snippet
public $analytics_endpoint = 'https://analytics.essentialplugin.com';
Explanation—
View raw JSON
{
    "slug": "blog-designer-for-post-and-widget",
    "pattern": "https://analytics.essentialplugin.com",
    "kind": "ioc:url",
    "version": "2.7.7.1",
    "hit_count": 5,
    "first_hit": {
        "file": "wpos-analytics/includes/class-anylc-admin.php",
        "line": 17,
        "snippet": "public $analytics_endpoint\t= 'https://analytics.essentialplugin.com';"
    },
    "explanation": null
}
Critical code_pattern Blog Designer – Post and Widget (4k+ installs) Malicious 5mo ago
Slugblog-designer-for-post-and-widget
Pattern$analytics_endpoint
Kindioc:code_pattern
Version2.7.7.1
Hit count1
First hit
File
wpos-analytics/includes/class-anylc-admin.php
Line
17
Snippet
public $analytics_endpoint = 'https://analytics.essentialplugin.com';
Explanation—
View raw JSON
{
    "slug": "blog-designer-for-post-and-widget",
    "pattern": "$analytics_endpoint",
    "kind": "ioc:code_pattern",
    "version": "2.7.7.1",
    "hit_count": 1,
    "first_hit": {
        "file": "wpos-analytics/includes/class-anylc-admin.php",
        "line": 17,
        "snippet": "public $analytics_endpoint\t= 'https://analytics.essentialplugin.com';"
    },
    "explanation": null
}
Critical code_pattern Blog Designer – Post and Widget (4k+ installs) Malicious 5mo ago
Slugblog-designer-for-post-and-widget
Patternwpos_monthly_cron_hook
Kindioc:code_pattern
Version2.7.7.1
Hit count4
First hit
File
wpos-analytics/includes/class-anylc-admin.php
Line
69
Snippet
add_action( 'wpos_monthly_cron_hook', array($this, 'wpos_monthly_cron_hook_fn') );
Explanation—
View raw JSON
{
    "slug": "blog-designer-for-post-and-widget",
    "pattern": "wpos_monthly_cron_hook",
    "kind": "ioc:code_pattern",
    "version": "2.7.7.1",
    "hit_count": 4,
    "first_hit": {
        "file": "wpos-analytics/includes/class-anylc-admin.php",
        "line": 69,
        "snippet": "add_action( 'wpos_monthly_cron_hook', array($this, 'wpos_monthly_cron_hook_fn') );"
    },
    "explanation": null
}
Critical code_pattern Featured Post Creative (1k+ installs) Malicious 5mo ago
Slugfeatured-post-creative
Patternunserialize_after_remote_call
Kindbuiltin
Version1.5.7.1
Hit count1
First hit
File
wpos-analytics/includes/class-anylc-admin.php
Line
696
Snippet
L690: $data = @file_get_contents($url); → L696: $info = @unserialize($data);
Explanationa remote HTTP fetch (`wp_remote_*` / `curl_exec`) is followed by `@unserialize` within the same file — classic PHP Object Injection C2 gadget. The error-suppressed form is the tell: legit code wants to know when deserialize fails; attackers suppress so malformed gadgets do not leak. A real finding regardless of author intent: any plugin that deserializes remote responses without validation is a latent RCE chain if the remote endpoint is ever compromised.
View raw JSON
{
    "slug": "featured-post-creative",
    "pattern": "unserialize_after_remote_call",
    "kind": "builtin",
    "version": "1.5.7.1",
    "hit_count": 1,
    "first_hit": {
        "file": "wpos-analytics/includes/class-anylc-admin.php",
        "line": 696,
        "snippet": "L690: $data = @file_get_contents($url);  \u2192  L696: $info = @unserialize($data);"
    },
    "explanation": "a remote HTTP fetch (`wp_remote_*` / `curl_exec`) is followed by `@unserialize` within the same file \u2014 classic PHP Object Injection C2 gadget. The error-suppressed form is the tell: legit code wants to know when deserialize fails; attackers suppress so malformed gadgets do not leak. A real finding regardless of author intent: any plugin that deserializes remote responses without validation is a latent RCE chain if the remote endpoint is ever compromised."
}
Critical code_pattern Featured Post Creative (1k+ installs) Malicious 5mo ago
Slugfeatured-post-creative
PatternWpos_Anylc_Admin
Kindioc:code_pattern
Version1.5.7.1
Hit count6
First hit
File
wpos-analytics/includes/class-anylc-admin.php
Line
15
Snippet
class Wpos_Anylc_Admin {
Explanation—
View raw JSON
{
    "slug": "featured-post-creative",
    "pattern": "Wpos_Anylc_Admin",
    "kind": "ioc:code_pattern",
    "version": "1.5.7.1",
    "hit_count": 6,
    "first_hit": {
        "file": "wpos-analytics/includes/class-anylc-admin.php",
        "line": 15,
        "snippet": "class Wpos_Anylc_Admin {"
    },
    "explanation": null
}
Critical code_pattern Featured Post Creative (1k+ installs) Malicious 5mo ago
Slugfeatured-post-creative
Patternwpos_rest_api_init
Kindioc:code_pattern
Version1.5.7.1
Hit count2
First hit
File
wpos-analytics/includes/class-anylc-admin.php
Line
72
Snippet
add_action( 'rest_api_init', array($this, 'wpos_rest_api_init') );
Explanation—
View raw JSON
{
    "slug": "featured-post-creative",
    "pattern": "wpos_rest_api_init",
    "kind": "ioc:code_pattern",
    "version": "1.5.7.1",
    "hit_count": 2,
    "first_hit": {
        "file": "wpos-analytics/includes/class-anylc-admin.php",
        "line": 72,
        "snippet": "add_action( 'rest_api_init', array($this, 'wpos_rest_api_init') );"
    },
    "explanation": null
}
Critical code_pattern Featured Post Creative (1k+ installs) Malicious 5mo ago
Slugfeatured-post-creative
Patternwpos_handle_analytics_request
Kindioc:code_pattern
Version1.5.7.1
Hit count2
First hit
File
wpos-analytics/includes/class-anylc-admin.php
Line
593
Snippet
'callback' => array( $this, 'wpos_handle_analytics_request' ),
Explanation—
View raw JSON
{
    "slug": "featured-post-creative",
    "pattern": "wpos_handle_analytics_request",
    "kind": "ioc:code_pattern",
    "version": "1.5.7.1",
    "hit_count": 2,
    "first_hit": {
        "file": "wpos-analytics/includes/class-anylc-admin.php",
        "line": 593,
        "snippet": "'callback'            => array( $this, 'wpos_handle_analytics_request' ),"
    },
    "explanation": null
}
Critical code_pattern Featured Post Creative (1k+ installs) Malicious 5mo ago
Slugfeatured-post-creative
Patternwpos_get_plugin_version_by_file
Kindioc:code_pattern
Version1.5.7.1
Hit count2
First hit
File
wpos-analytics/includes/class-anylc-admin.php
Line
657
Snippet
$version = $this->wpos_get_plugin_version_by_file($matching_product['file']);
Explanation—
View raw JSON
{
    "slug": "featured-post-creative",
    "pattern": "wpos_get_plugin_version_by_file",
    "kind": "ioc:code_pattern",
    "version": "1.5.7.1",
    "hit_count": 2,
    "first_hit": {
        "file": "wpos-analytics/includes/class-anylc-admin.php",
        "line": 657,
        "snippet": "$version = $this->wpos_get_plugin_version_by_file($matching_product['file']);"
    },
    "explanation": null
}