Hi @netmagik
This file is used for dependency management of PHP, the language the plugin is written in, as is WordPress.
It is widely used by many plugins, themes, and other PHP software and is not malware. You can find some information here about composer.
I don’t know why they triggered on this commonly used manager. You can find our plugin risk score here: https://coderisk.com/wp/plugin/complianz-gdpr
Also refer to this thread for more information.
By any chance, are you using ‘Greengeeks’?
We will consider removing this composer file with our next update to prevent these false positives.
Kind regards,
Leon