http://wordpress.org/extend/plugins/wp-google-plus-one/ appears to be a tool for an online casino to scam +1 votes. It does not appear to be malicious or phish, but it's certainly not going to do "what it says on the box". I'm not sure if there's a way to notify the repo maintainers?