I downloaded it and got the warning when I installed it (I'd already run it
before the scan finished, which is how I know it is not a false alarm, because
it changed my plugin media settings to autorun.)
Afterwards, I downloaded a fresh copy of the tgz file from the DokuWiki site
and uploaded it to VirusTotal. The list of detections I sent in my first
message is from VirusTotal and the fresh download I uploaded to it.
BitDefender on my system said it was the sqlite3.dll file that was infected.
VirusTotal didn't give me any info on individual files that triggered the
detections.
‐‐‐‐‐‐‐ Original Message ‐‐‐‐‐‐‐
How did you detect this? Is this on your local installation, or by testing
the direct download from https://download.dokuwiki.org?