Can't edit my post becuase it's been too long:
Update: Well then, people have been using this for over 2 years and no one's thought to check it for backdoors or trojans? Lol, I would recommend that you not install run this on a live server, or home computer / vpn. It's not worth it.
It has a PHP Shell backdoor Backdoor.Small!1.A2CD (classic)
Here's a virus total of the package after deobscureicating the file curl_mailer.php
More Proof:
Whoever did it was kind enough to put their name at the top...
I'll clean it and test it to see if the methods still any good or not, if it is I'll upload a cleaned copy of it.
Seeing as this one is dirty, I would ventrue a guess that this guys
other one for holister is also dirty, but I haven't checked yet