marcocesarato/amwscan

AMWSCAN (Antimalware Scanner) is a php antimalware/antivirus scanner console script written in php for scan your project. This can work on php projects and a lot of others platform.

Maintainers

Package info

github.com/marcocesarato/PHP-Antimalware-Scanner

Type:console

pkg:composer/marcocesarato/amwscan

Transparency log

Statistics

Installs: 20 703

Dependents: 1

Suggesters: 0

Stars: 779

Open Issues: 36

0.16.0 2026-08-25 20:48 UTC

README

Version

PHP Antimalware Scanner

Version Requirements Code Style License GitHub

If this project helped you out, please support us with a star ⭐

Documentation

Description

PHP Antimalware Scanner is a free tool to scan PHP files and analyze your project to find any malicious code inside it.

It provides an interactive text terminal console interface to scan a file, or all files in a given directory (file paths can also be managed using --filter-paths or --ignore-paths), and find PHP code files that seem to contain malicious code. When a probable malware is detected, will be asked what action to take (like add to the whitelist, delete files, try clean infected code, etc).

The package can also scan the PHP files in a report mode (--report|-r), so without interacting and outputting anything to the terminal console. In that case, the results will be stored in a report file in HTML (default) or text format (--report-format <format>).

This scanner can work on your own php projects and on a lot of other platforms using the right combination of configurations (ex. using --lite|-l flag can help to find less false positivity).

⚠️ Remember that you will be solely responsible for any damage to your computer system or loss of data that results from such activities. You are solely responsible for adequate protection and backup of the data before executing the scanner.

How to contribute

Have an idea? Found a bug? Please raise to ISSUES or PULL REQUEST. Contributions are welcome and are greatly appreciated! Every little bit helps.

WordPress report findings include a Report finding action that drafts a public issue with signature metadata and the file SHA-256, while excluding local paths and matched code. Do not upload executable malware to a public issue; maintainers can arrange a private sample transfer when needed.

Releases

  • Update version number in composer.json
  • Update composer hash with composer update --lock
  • Build a phar file for dist/scanner
  • Update version number in dist/version
  • Commit and set Git tag
  • Add release on GitHub
  • Celebrate 🥳

WordPress plugin releases

The Antimalware Scanner dashboard automatically refreshes active scan status, shows elapsed and estimated remaining time, and summarizes recent activity, including the total threats found in retained reports. Settings use a server-side folder explorer for local scan and private storage paths, or a validated FTP/FTPS URL for read-only remote scans. FTP passwords remain in the server environment and are never saved in WordPress. The active plugin directory and private scanner data are always excluded from local scans. An About screen links installed version details and project credits to the plugin guide, scanner documentation, contribution guidance, and support.

WordPress plugin releases use separate wordpress-vX.Y.Z tags:

composer plugin:release:prepare -- 0.2.0  # update, test, and package only
composer plugin:release -- 0.2.0          # commit, tag, push, and trigger GitHub release

The tag workflow publishes the installable ZIP with GitHub-generated release notes. Publication requires a synchronized main or master branch; suffixed versions become prereleases. See plugins/wordpress/README.md for the complete process.

📘 Requirements

  • php 7.4+ (PHP 8.x recommended)
    • php-xml
    • php-zip
    • php-mbstring
    • php-json
    • php-common
    • php-curl
    • php-ftp (optional, required for FTP scans)
    • php-gd

📖 Install

WordPress Plugin

Download and copy to wp-content/plugins/amwscan-antimalware, then activate Antimalware Scanner in WordPress. See the WordPress plugin guide for configuration and release details.

Download

Release

You can use one of these methods to install the scanner by downloading it from GitHub or directly from the console.

Download

Go to the GitHub page and press on the Releases tab or download the raw file from:

Download

Console

  1. Run this command from the console (the scanner will be downloaded to your current directory):

    wget https://raw.githubusercontent.com/marcocesarato/PHP-Antimalware-Scanner/master/dist/scanner

  2. Run the scanner:

    php scanner ./dir-to-scan -l ...

  3. (Optional) Install as bin command (Unix Bash)

    Run this command:

    wget https://raw.githubusercontent.com/marcocesarato/PHP-Antimalware-Scanner/master/dist/scanner -O /usr/bin/awscan.phar && \
    printf '#!/bin/bash\nphp /usr/bin/awscan.phar $@' > /usr/bin/awscan && \
    chmod u+x,g+x /usr/bin/awscan.phar && \
    chmod u+x,g+x /usr/bin/awscan && \
    export PATH=$PATH":/usr/bin"

    Now you can run the scanner simply with this command: awscan ./dir-to-scan -l...

Composer

The package is available on Packagist.

Global Installation (recommended)

For system-wide installation, use:

composer global require marcocesarato/amwscan

After installation, run the scanner using:

php $(composer global config home)/vendor/marcocesarato/amwscan/src/index.php <path-to-scan> [options]

Or create an alias for easier usage:

alias amwscan='php $(composer global config home)/vendor/marcocesarato/amwscan/src/index.php'

Then you can run: amwscan <path-to-scan> [options]

Project-Level Installation

For installing within a specific project:

composer require marcocesarato/amwscan

After installation, run the scanner using:

php vendor/marcocesarato/amwscan/src/index.php <path-to-scan> [options]

Source

Download

Click the GitHub page "Clone or download" or download from:

Download

Git
  1. Install git
  2. Copy the command and link from below in your terminal: git clone https://github.com/marcocesarato/PHP-Antimalware-Scanner
  3. Change directories to the new ~/PHP-Antimalware-Scanner directory: cd ~/PHP-Antimalware-Scanner/
  4. To ensure that your master branch is up-to-date, use the pull command: git pull https://github.com/marcocesarato/PHP-Antimalware-Scanner
  5. Enjoy

🐳 Docker

  1. Download the source
  2. Build command docker build --tag amwscan-docker .
  3. Run command docker run -it --rm amwscan-docker bash

🧪 Testing

The project includes a comprehensive test suite with unit and integration tests.

Running Tests

# Run all tests
composer test

# Run only unit tests
composer test:unit

# Run only integration tests
composer test:integration

# Generate coverage report
composer test:coverage

Writing Tests

Tests are organized into:

  • Unit Tests (tests/Unit/) - Fast, isolated tests for individual classes
  • Integration Tests (tests/Integration/) - CLI execution tests with various configurations
  • Test Fixtures (tests/Fixtures/) - Sample files for testing (clean, malware, obfuscated)

For detailed information on writing and debugging tests, see TESTING.md.

Continuous Integration

Tests run automatically on pull requests and pushes across multiple PHP versions (7.4, 8.0, 8.1, 8.2, 8.3).

🔎 Scanning mode

The first think you need to decide is the strength, you need to calibrate your scan to find less false positive as possible during scanning without miss for real malware. For this you can choose the aggression level.

The scanner permit to have some predefined modes:

Mode Alias 🚀 Description
None (default) 🔴 Search for all functions, exploits and malware signs without any restrictions
Only exploits -e 🟠 Search only for exploits definitions
Use flag: --only-exploits
Lite mode -l 🟡 Search for exploits with some restrictions and malware signs (on Wordpress and others platform could detect less false positivity)
Use flag: --lite
Only functions -f 🟡 Search only for functions (on some obfuscated code functions couldn't be detected)
Use flag: --only-functions
Only signatures -s 🟢 Search only for malware signatures (could be a good solution for Wordpress and others platform to detect less false positivity)
Use flag: --only-signatures

💻 Usage

Command line

php amwscan ./mywebsite/http/ -l -s --only-exploits
php amwscan -s --max-filesize="5MB"
php amwscan -s -logs="/user/marco/scanner.log"
php amwscan --lite --only-exploits
php amwscan --exploits="double_var2" --functions="eval, str_replace"
php amwscan --ignore-paths="/my/path/*.log,/my/path/*/cache/*"
php amwscan --debug ./mywebsite/http/

Use --debug only while troubleshooting. It displays PHP runtime errors and warnings for the current scan.

Doesn't work?

In case above command doesn't work, you can use script responsible for malware scan manually by executing: php dist/scanner <path>

To check all options check the Documentation

Suggestions

If you are running the scanner on a Wordpress project or other popular platform use --only-signatures or --lite flag to have check with less false positive but this could miss some dangerous exploits like nano.

Platform checksum verification

Checksum verification is enabled by default for WordPress and WordPress plugins such as WooCommerce, as well as Joomla, Drupal, Magento Open Source, and public Composer packages. The scanner detects the installed version and retrieves per-file checksums from the platform's official API or release repository. Composer package manifests are derived from the exact distribution archive independently resolved through Packagist. Files whose bytes exactly match an official release are skipped; modified, generated, and untracked files are still scanned.

The first scan of a platform or package version requires outbound HTTPS access. Successful checksum manifests are cached locally. Unsupported packages and unavailable metadata fail open and are scanned normally. Use --disable-checksum to avoid checksum requests and scan every matching file.

Programmatically

On programmatically silent mode and auto skip are automatically enabled.

use AMWScan\Scanner;

$app = new Scanner();
$report = $app->setPathScan("my/path/to/scan")
              ->enableBackups()
              ->setPathBackups("/my/path/backups")
              ->enableLiteMode()
              ->setAutoClean()
              ->run();
Report Object
object(stdClass) (7) {
  ["scanned"]    => int(0)
  ["detected"]   => int(0)
  ["removed"]    => array(0) {}
  ["ignored"]    => array(0) {}
  ["edited"]     => array(0) {}
  ["quarantine"] => array(0) {}
  ["whitelist"]  => array(0) {}
}

🎨 Screenshots

WordPress dashboard

Screen Dashboard

Report

HTML report format (default)

Screen Report

Interactive CLI

Screen Full