Command-line scanner for malicious PHP files and compromised projects
4.3K
Run PHP Antimalware Scanner inside Docker to scan PHP projects and WordPress installations for suspicious code, integrity changes, and known malware patterns.
Documentation | Latest release | GitHub | GitHub Action | WordPress.org plugin
Pull the latest image:
docker pull marcocesarato/php-antimalware-scanner:latest
Scan a project safely using a read-only volume:
docker run --rm \
--volume "/path/to/project:/scan:ro" \
marcocesarato/php-antimalware-scanner:latest /scan \
--lite --report-only
--report-only performs a non-destructive scan and does not automatically modify detected files.
Caution
Review detections before cleaning, quarantining, or deleting files. A detection identifies suspicious code but does not necessarily mean that the complete file is malicious.
Mount a writable directory for reports:
docker run --rm \
--volume "/path/to/project:/scan:ro" \
--volume "$PWD/amwscan-output:/output" \
marcocesarato/php-antimalware-scanner:latest /scan \
--lite \
--report-only \
--report-format=html \
--path-report=/output/report.html
The report will be available on the host at:
./amwscan-output/report.html
Available report formats include:
html
text
json
sarif
For automation, JSON or SARIF are usually the most useful:
docker run --rm \
--volume "$PWD:/scan:ro" \
--volume "$PWD/amwscan-output:/output" \
marcocesarato/php-antimalware-scanner:latest /scan \
--lite \
--report-only \
--report-format=sarif \
--path-report=/output/report.sarif
The recommended setup uses separate volumes for the files being scanned and generated output:
--volume "/path/to/project:/scan:ro"
--volume "/path/to/output:/output"
| Container path | Purpose | Recommended access |
|---|---|---|
/scan | Project or WordPress installation to scan | Read-only |
/output | Reports and other generated files | Read/write |
Using /scan:ro prevents the scanner from modifying the scanned project.
If you intentionally use scanner features that modify, quarantine, or clean files, mount the scan directory without :ro.
The scanner supports several modes.
| Mode | Option | Description |
|---|---|---|
| Full | No mode option | Broadest scan |
| Lite | --lite, -l | Practical default with fewer noisy matches |
| Signatures | --only-signatures, -s | Scan for known malware signatures |
| Exploits | --only-exploits, -e | Scan suspicious code structures |
| Functions | --only-functions, -f | Review dangerous PHP function calls |
For most Docker scans, start with:
--lite --report-only
See the complete CLI options reference for all available options.
From inside your project:
docker run --rm \
--volume "$PWD:/scan:ro" \
marcocesarato/php-antimalware-scanner:latest /scan \
--lite --report-only
With an HTML report:
mkdir -p amwscan-output
docker run --rm \
--volume "$PWD:/scan:ro" \
--volume "$PWD/amwscan-output:/output" \
marcocesarato/php-antimalware-scanner:latest /scan \
--lite \
--report-only \
--report-format=html \
--path-report=/output/report.html
Archive scanning can be enabled with:
docker run --rm \
--volume "$PWD:/scan:ro" \
marcocesarato/php-antimalware-scanner:latest /scan \
--lite \
--report-only \
--scan-archives
Generated directories such as caches and logs can be excluded:
docker run --rm \
--volume "$PWD:/scan:ro" \
marcocesarato/php-antimalware-scanner:latest /scan \
--lite \
--report-only \
--ignore-paths="*/cache/*,*/logs/*"
For a local WordPress installation:
docker run --rm \
--volume "/path/to/wordpress:/scan:ro" \
--volume "$PWD/amwscan-output:/output" \
marcocesarato/php-antimalware-scanner:latest /scan \
--scan-wordpress-db \
--report-only \
--report-format=json \
--path-report=/output/report.json
Database checks are optional and depend on the WordPress environment being accessible from inside the container.
For the complete WordPress integration, see the WordPress plugin documentation.
Normal scans can use the definitions bundled with the scanner.
Some functionality, including remote definition updates and platform integrity checks, may require outbound HTTPS access.
For isolated or reproducible scans, remote updates can be disabled:
docker run --rm \
--volume "$PWD:/scan:ro" \
marcocesarato/php-antimalware-scanner:latest /scan \
--lite \
--report-only \
--disable-checksum \
--disable-definitions-update
You can additionally disable container networking with Docker:
docker run --rm \
--network none \
--volume "$PWD:/scan:ro" \
marcocesarato/php-antimalware-scanner:latest /scan \
--lite \
--report-only \
--disable-checksum \
--disable-definitions-update
Example compose.yaml:
services:
amwscan:
image: marcocesarato/php-antimalware-scanner:latest
volumes:
- ./:/scan:ro
- ./amwscan-output:/output
command:
- /scan
- --lite
- --report-only
- --report-format=html
- --path-report=/output/report.html
Run it with:
docker compose run --rm amwscan
The scanner uses exit codes suitable for scripts and CI/CD pipelines.
In particular:
0 Scan completed without detected security issues
1 Security issue detected
2 Scanner could not complete successfully
When using the image in automation, check the container exit code rather than parsing console output.
For GitHub Actions, the dedicated integration is usually more convenient than manually running the Docker image:
PHP Antimalware Security Scan — GitHub Marketplace
Documentation for GitHub Actions, GitLab CI, Jenkins, SARIF, and other automation workflows is available in the CI/CD guide.
The Docker image is one of several ways to use PHP Antimalware Scanner:
Documentation is available in English, Italian, German, French, Spanish, Russian, Simplified Chinese, Japanese, Hindi, and Arabic.
PHP Antimalware Scanner is available under the GNU General Public License 3.0 or later.
Content type
Image
Digest
sha256:487914de5…
Size
47.2 MB
Last updated
2 days ago
docker pull marcocesarato/php-antimalware-scanner