Hacker News new | ask | show | jobs
by claudiulodro 524 days ago
Looking at it, it has some code to make itself appear inactive when looking at the Plugins screen but it is almost certainly active.

Judging by the gmv and pun_ajax_handler functions (which are heavily obfuscated), it's malicious and your site got hacked somehow (probably weak user creds or outdated plugins). I recommend running Jetpack Scan or some other WP security scanner.