> For clean Markdown of any page, append .md to the page URL. > For a complete documentation index, see https://api.docs.modulards.com/modular-ds-public-api/malware-scanner/findings/list-malware-scan-findings/llms.txt. > For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://api.docs.modulards.com/_mcp/server. # List malware scan findings GET https://api.modulards.com/api/public/v1/site-scan-items Lists the findings of your malware scans, newest first. Use `filter[site_scan][]` for the findings of one scan, or `filter[site][]` for every finding of a website across scans. Each finding is a file or a database threat. Its `threat_category` says what it needs: `infected` is cleaned by replacing content, `malicious` is deleted or truncated and `suspicious` needs a human decision. The raw file hash and the malware signature name are never exposed. Reference: https://api.docs.modulards.com/modular-ds-public-api/malware-scanner/findings/list-malware-scan-findings ## Authentication - `Authorization` header (bearer token, required) — Personal access token created in the Modular DS dashboard; read-only tokens can only call GET endpoints. ## Request ### Query parameters - `filter[id][]` (string, optional) — Exact finding ids. Repeat the parameter for several. - `filter[site_scan][]` (string, optional) — Exact scan ids: the findings of those scans. Repeat the parameter for several. - `filter[site][]` (string, optional) — Exact website ids: every finding of those websites across scans. Repeat the parameter for several. - `filter[type][]` (string, optional) — Where the finding came from: `file` or `database`. Repeat the parameter for several. - `filter[severity][]` (string, optional) — `low`, `medium`, `high` or `critical`. Repeat the parameter for several. - `filter[threat_category][]` (string, optional) — `infected`, `malicious` or `suspicious`. Repeat the parameter for several. - `filter[status][]` (string, optional) — `detected`, `ignored` or `failed`. Repeat the parameter for several. - `sort` (string, optional) — `created_at` or `severity`; prefix with `-` for descending. Default: `-created_at`. `-severity` lists critical findings first. - `page[number]` (string, optional) — Page number, starting at 1. Default 1. - `page[size]` (string, optional) — Items per page, 1 to 50. Default 15. ## Response ### 200 200 - Scan findings list - `data` (list of ApiPublicV1SiteScanItemsGetResponsesContentApplicationJsonSchemaDataItems, optional) - `jsonapi` (ApiPublicV1SiteScanItemsGetResponsesContentApplicationJsonSchemaJsonapi, optional) - `links` (ApiPublicV1SiteScanItemsGetResponsesContentApplicationJsonSchemaLinks, optional) - `meta` (ApiPublicV1SiteScanItemsGetResponsesContentApplicationJsonSchemaMeta, optional) ## Types ### ApiPublicV1SiteScanItemsGetResponsesContentApplicationJsonSchemaDataItems - `attributes` (ApiPublicV1SiteScanItemsGetResponsesContentApplicationJsonSchemaDataItemsAttributes, optional) - `id` (string, optional) - `type` (string, optional) ### ApiPublicV1SiteScanItemsGetResponsesContentApplicationJsonSchemaJsonapi - `version` (string, optional) ### ApiPublicV1SiteScanItemsGetResponsesContentApplicationJsonSchemaLinks - `first` (string, optional) - `last` (string, optional) - `next` (any, optional, nullable) - `prev` (any, optional, nullable) ### ApiPublicV1SiteScanItemsGetResponsesContentApplicationJsonSchemaMeta - `current_page` (double, optional) - `from` (double, optional) - `last_page` (double, optional) - `links` (list of ApiPublicV1SiteScanItemsGetResponsesContentApplicationJsonSchemaMetaLinksItems, optional) - `path` (string, optional) - `per_page` (double, optional) - `to` (double, optional) - `total` (double, optional) ### ApiPublicV1SiteScanItemsGetResponsesContentApplicationJsonSchemaDataItemsAttributes - `column_name` (string, optional, nullable) — Database column of the finding; set for database findings. - `created_at` (datetime, optional) — When the finding was recorded. - `path` (string, optional, nullable) — Path of the affected file; set for file findings. - `severity` (enum, optional) — How serious the finding is. - Allowed values: `low`, `medium`, `high`, `critical` - `site_scan_id` (integer, optional) — Id of the malware scan that made the finding. - `status` (enum, optional) — What became of the finding: detected, ignored or failed. - Allowed values: `detected`, `ignored`, `failed` - `table_name` (string, optional, nullable) — Database table of the finding; set for database findings. - `threat_category` (enum, optional) — Kind of threat and the way it is handled: infected (injected into a legitimate file; cleaned by replacing its content), malicious (standalone malware; deleted or truncated) or suspicious (needs a human decision). - Allowed values: `infected`, `malicious`, `suspicious` - `type` (enum, optional) — Where the finding was made: in a file or in the website database. - Allowed values: `file`, `database` ### ApiPublicV1SiteScanItemsGetResponsesContentApplicationJsonSchemaMetaLinksItems - `active` (boolean, optional) - `label` (string, optional) - `url` (string, optional, nullable) ## Examples **Response** ```json { "data": [ { "attributes": { "column_name": null, "created_at": "2026-09-18T09:12:00.000000Z", "path": "wp-content/uploads/2026/09/shell.php", "severity": "critical", "site_scan_id": 3021, "status": "detected", "table_name": null, "threat_category": "infected", "type": "file" }, "id": "9931", "type": "site-scan-items" }, { "attributes": { "column_name": "post_content", "created_at": "2026-09-18T09:13:00.000000Z", "path": null, "severity": "medium", "site_scan_id": 3021, "status": "detected", "table_name": "wp_posts", "threat_category": "suspicious", "type": "database" }, "id": "9932", "type": "site-scan-items" } ], "jsonapi": { "version": "1.1" }, "links": { "first": "{{base_url}}/api/public/v1/site-scan-items?page%5Bnumber%5D=1", "last": "{{base_url}}/api/public/v1/site-scan-items?page%5Bnumber%5D=1", "next": null, "prev": null }, "meta": { "current_page": 1, "from": 1, "last_page": 1, "links": [ { "active": false, "label": "« Previous", "url": null }, { "active": true, "label": "1", "url": "{{base_url}}/api/public/v1/site-scan-items?page%5Bnumber%5D=1" }, { "active": false, "label": "Next »", "url": null } ], "path": "{{base_url}}/api/public/v1/site-scan-items", "per_page": 15, "to": 2, "total": 2 } } ``` **SDK Code** ```python 200 - Scan findings list import requests url = "https://api.modulards.com/api/public/v1/site-scan-items" headers = {"Authorization": "Bearer "} response = requests.get(url, headers=headers) print(response.json()) ``` ```javascript 200 - Scan findings list const url = 'https://api.modulards.com/api/public/v1/site-scan-items'; const options = {method: 'GET', headers: {Authorization: 'Bearer '}}; try { const response = await fetch(url, options); const data = await response.json(); console.log(data); } catch (error) { console.error(error); } ``` ```go 200 - Scan findings list package main import ( "fmt" "net/http" "io" ) func main() { url := "https://api.modulards.com/api/public/v1/site-scan-items" req, _ := http.NewRequest("GET", url, nil) req.Header.Add("Authorization", "Bearer ") res, _ := http.DefaultClient.Do(req) defer res.Body.Close() body, _ := io.ReadAll(res.Body) fmt.Println(res) fmt.Println(string(body)) } ``` ```ruby 200 - Scan findings list require 'uri' require 'net/http' url = URI("https://api.modulards.com/api/public/v1/site-scan-items") http = Net::HTTP.new(url.host, url.port) http.use_ssl = true request = Net::HTTP::Get.new(url) request["Authorization"] = 'Bearer ' response = http.request(request) puts response.read_body ``` ```java 200 - Scan findings list import com.mashape.unirest.http.HttpResponse; import com.mashape.unirest.http.Unirest; HttpResponse response = Unirest.get("https://api.modulards.com/api/public/v1/site-scan-items") .header("Authorization", "Bearer ") .asString(); ``` ```php 200 - Scan findings list request('GET', 'https://api.modulards.com/api/public/v1/site-scan-items', [ 'headers' => [ 'Authorization' => 'Bearer ', ], ]); echo $response->getBody(); ``` ```csharp 200 - Scan findings list using RestSharp; var client = new RestClient("https://api.modulards.com/api/public/v1/site-scan-items"); var request = new RestRequest(Method.GET); request.AddHeader("Authorization", "Bearer "); IRestResponse response = client.Execute(request); ``` ```swift 200 - Scan findings list import Foundation let headers = ["Authorization": "Bearer "] let request = NSMutableURLRequest(url: NSURL(string: "https://api.modulards.com/api/public/v1/site-scan-items")! as URL, cachePolicy: .useProtocolCachePolicy, timeoutInterval: 10.0) request.httpMethod = "GET" request.allHTTPHeaderFields = headers let session = URLSession.shared let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in if (error != nil) { print(error as Any) } else { let httpResponse = response as? HTTPURLResponse print(httpResponse) } }) dataTask.resume() ```