{"repo":"scr34m/php-malware-scanner","free":true,"listed":false,"github":"https://github.com/scr34m/php-malware-scanner","clone":"git clone https://github.com/scr34m/php-malware-scanner.git","description":"Scans PHP files for malwares and known threats","language":"PHP","stars":605,"topics":["php","malware","command-line-tool","scanner"],"license":"GPL-3.0","category":"cli-tools","readme_excerpt":"PHP malware scanner =================== Traversing directories for files with php extensions and testing files against text or regexp rules, the rules based on self gathered samples and publicly available malwares/webshells. The goal is to find infected files and fight against kiddies, because to easy to bypass rules. How to install? --- Simply clone the repository or with composer install globally composer global require scr34m/php-malware-scanner . How to use? ----------- Ignore argument could be used multiple times and accept glob style matching ex.: \" cache \", \" ??-cache.php \" or \" /cache \" etc. Extension argument defaults to \" .php \" and also can be used multiple times too. --base64 is an alternative scan mode which ignores the main pattern files and uses a large list of php keywords and functions that have been converted to base64. Slower and prone to false positives, but gives additional base64 scanning coverage. These pattern files are located in base64 patterns and were derived from php 7 keywords and functions. Not many PHP extensions are included. --comment flag will display the last comment to appear in the pattern file before the matched pattern, so documenting the pattern files is important. Output formatting ----------------- Default output depending on the specified parameters, but the full format is \"%S %T %M # {%F} %C %P # %L\" and using ANSI coloring too. Possible variables are: %S - matching indicator, possible values are OK, ER, WL %T - file change time %M","default_branch":null,"files":null,"tree":[],"storefront":"/r/scr34m","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/scr34m/php-malware-scanner/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}