Skip to navigation

Launch malware scans

View as MarkdownOpen in Claude

Launches a malware scan on each website you list in sites, one scan per website, over each website’s configured areas unless included names them. Each website’s own exclusions always apply.

A manual scan uses the website’s scan quota and does not move its scheduled scan. A scan can take hours: follow the launched scans with “List malware scans” (filter[id][]) and read status and verdict. The work finishes later: see Writes and asynchronous operations. Websites that cannot be processed are reported in meta.skipped, each with a reason_code and a message, and do not fail the call. The first matching reason wins: PERMISSION_DENIED (a website your token cannot reach, with a null site_name), SITE_UNREACHABLE (disconnected), UNSUPPORTED (no Malware Scanner configuration, or not yet registered with the scanning provider), CONFLICT (a scan of that website is already running) and QUOTA_EXCEEDED (no scan quota left for any of the requested areas this period; the message carries the reset date). When only some of the requested areas have quota left, the scan still runs on those areas and meta.warnings names each area left out.

Body

  • sites (array of integers, required): ids of the websites to act on, 1 to 50.
  • included (array of strings, optional): areas to scan instead of each website’s configured ones: core, plugins, themes, mu_plugins, content, uploads, database.

Authentication

AuthorizationBearer

Personal access token created in the Modular DS dashboard; read-only tokens can only call GET endpoints.

Request

This endpoint expects an object.
includedlist of stringsOptional
siteslist of doublesOptional

Response

202 - Scans launched, two skipped

datalist of objectsOptional
jsonapiobjectOptional
metaobjectOptional