Sign inSign up

marcocesarato/php-antimalware-scanner

By marcocesarato

•Updated 2 days ago

Command-line scanner for malicious PHP files and compromised projects

Image
Security
0

4.3K

marcocesarato/php-antimalware-scanner repository overview

⁠PHP Antimalware Scanner — Docker

Run PHP Antimalware Scanner⁠ inside Docker to scan PHP projects and WordPress installations for suspicious code, integrity changes, and known malware patterns.

License Documentation

Documentation⁠ | Latest release⁠ | GitHub⁠ | GitHub Action⁠ | WordPress.org plugin⁠

⁠Quick start

Pull the latest image:

docker pull marcocesarato/php-antimalware-scanner:latest

Scan a project safely using a read-only volume:

docker run --rm \
  --volume "/path/to/project:/scan:ro" \
  marcocesarato/php-antimalware-scanner:latest /scan \
  --lite --report-only

--report-only performs a non-destructive scan and does not automatically modify detected files.

Caution

Review detections before cleaning, quarantining, or deleting files. A detection identifies suspicious code but does not necessarily mean that the complete file is malicious.

⁠Generate a report

Mount a writable directory for reports:

docker run --rm \
  --volume "/path/to/project:/scan:ro" \
  --volume "$PWD/amwscan-output:/output" \
  marcocesarato/php-antimalware-scanner:latest /scan \
  --lite \
  --report-only \
  --report-format=html \
  --path-report=/output/report.html

The report will be available on the host at:

./amwscan-output/report.html

Available report formats include:

html
text
json
sarif

For automation, JSON or SARIF are usually the most useful:

docker run --rm \
  --volume "$PWD:/scan:ro" \
  --volume "$PWD/amwscan-output:/output" \
  marcocesarato/php-antimalware-scanner:latest /scan \
  --lite \
  --report-only \
  --report-format=sarif \
  --path-report=/output/report.sarif

⁠Volume mounts

The recommended setup uses separate volumes for the files being scanned and generated output:

--volume "/path/to/project:/scan:ro"
--volume "/path/to/output:/output"
Container pathPurposeRecommended access
/scanProject or WordPress installation to scanRead-only
/outputReports and other generated filesRead/write

Using /scan:ro prevents the scanner from modifying the scanned project.

If you intentionally use scanner features that modify, quarantine, or clean files, mount the scan directory without :ro.

⁠Scan modes

The scanner supports several modes.

ModeOptionDescription
FullNo mode optionBroadest scan
Lite--lite, -lPractical default with fewer noisy matches
Signatures--only-signatures, -sScan for known malware signatures
Exploits--only-exploits, -eScan suspicious code structures
Functions--only-functions, -fReview dangerous PHP function calls

For most Docker scans, start with:

--lite --report-only

See the complete CLI options reference⁠ for all available options.

⁠Scan the current directory

From inside your project:

docker run --rm \
  --volume "$PWD:/scan:ro" \
  marcocesarato/php-antimalware-scanner:latest /scan \
  --lite --report-only

With an HTML report:

mkdir -p amwscan-output

docker run --rm \
  --volume "$PWD:/scan:ro" \
  --volume "$PWD/amwscan-output:/output" \
  marcocesarato/php-antimalware-scanner:latest /scan \
  --lite \
  --report-only \
  --report-format=html \
  --path-report=/output/report.html

⁠Scan ZIP archives

Archive scanning can be enabled with:

docker run --rm \
  --volume "$PWD:/scan:ro" \
  marcocesarato/php-antimalware-scanner:latest /scan \
  --lite \
  --report-only \
  --scan-archives

⁠Ignore directories

Generated directories such as caches and logs can be excluded:

docker run --rm \
  --volume "$PWD:/scan:ro" \
  marcocesarato/php-antimalware-scanner:latest /scan \
  --lite \
  --report-only \
  --ignore-paths="*/cache/*,*/logs/*"

⁠WordPress database scan

For a local WordPress installation:

docker run --rm \
  --volume "/path/to/wordpress:/scan:ro" \
  --volume "$PWD/amwscan-output:/output" \
  marcocesarato/php-antimalware-scanner:latest /scan \
  --scan-wordpress-db \
  --report-only \
  --report-format=json \
  --path-report=/output/report.json

Database checks are optional and depend on the WordPress environment being accessible from inside the container.

For the complete WordPress integration, see the WordPress plugin documentation⁠.

⁠Definitions and network access

Normal scans can use the definitions bundled with the scanner.

Some functionality, including remote definition updates and platform integrity checks, may require outbound HTTPS access.

For isolated or reproducible scans, remote updates can be disabled:

docker run --rm \
  --volume "$PWD:/scan:ro" \
  marcocesarato/php-antimalware-scanner:latest /scan \
  --lite \
  --report-only \
  --disable-checksum \
  --disable-definitions-update

You can additionally disable container networking with Docker:

docker run --rm \
  --network none \
  --volume "$PWD:/scan:ro" \
  marcocesarato/php-antimalware-scanner:latest /scan \
  --lite \
  --report-only \
  --disable-checksum \
  --disable-definitions-update

⁠Docker Compose

Example compose.yaml:

services:
  amwscan:
    image: marcocesarato/php-antimalware-scanner:latest
    volumes:
      - ./:/scan:ro
      - ./amwscan-output:/output
    command:
      - /scan
      - --lite
      - --report-only
      - --report-format=html
      - --path-report=/output/report.html

Run it with:

docker compose run --rm amwscan

⁠Exit codes

The scanner uses exit codes suitable for scripts and CI/CD pipelines.

In particular:

0  Scan completed without detected security issues
1  Security issue detected
2  Scanner could not complete successfully

When using the image in automation, check the container exit code rather than parsing console output.

⁠CI/CD

For GitHub Actions, the dedicated integration is usually more convenient than manually running the Docker image:

PHP Antimalware Security Scan — GitHub Marketplace⁠

Documentation for GitHub Actions, GitLab CI, Jenkins, SARIF, and other automation workflows is available in the CI/CD guide⁠.

⁠Other distributions

The Docker image is one of several ways to use PHP Antimalware Scanner:

Documentation is available in English, Italian, German, French, Spanish, Russian, Simplified Chinese, Japanese, Hindi, and Arabic.

⁠License

PHP Antimalware Scanner is available under the GNU General Public License 3.0 or later⁠.

Tag summary

Content type

Image

Digest

sha256:487914de5…

Size

47.2 MB

Last updated

2 days ago

docker pull marcocesarato/php-antimalware-scanner