> For clean Markdown of any page, append .md to the page URL. > For a complete documentation index, see https://api.docs.modulards.com/modular-ds-public-api/malware-scanner/malware-scans/launch-malware-scans/llms.txt. > For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://api.docs.modulards.com/_mcp/server. # Launch malware scans POST https://api.modulards.com/api/public/v1/site-scans Content-Type: application/json Launches a malware scan on each website you list in `sites`, one scan per website, over each website's configured areas unless `included` names them. Each website's own exclusions always apply. A manual scan uses the website's scan quota and does not move its scheduled scan. A scan can take hours: follow the launched scans with "List malware scans" (`filter[id][]`) and read `status` and `verdict`. The work finishes later: see [Writes and asynchronous operations](https://api.docs.modulards.com/writes-and-asynchronous-operations). Websites that cannot be processed are reported in `meta.skipped`, each with a `reason_code` and a message, and do not fail the call. The first matching reason wins: `PERMISSION_DENIED` (a website your token cannot reach, with a null `site_name`), `SITE_UNREACHABLE` (disconnected), `UNSUPPORTED` (no Malware Scanner configuration, or not yet registered with the scanning provider), `CONFLICT` (a scan of that website is already running) and `QUOTA_EXCEEDED` (no scan quota left for any of the requested areas this period; the message carries the reset date). When only some of the requested areas have quota left, the scan still runs on those areas and `meta.warnings` names each area left out. **Body** - `sites` (array of integers, required): ids of the websites to act on, 1 to 50. - `included` (array of strings, optional): areas to scan instead of each website's configured ones: `core`, `plugins`, `themes`, `mu_plugins`, `content`, `uploads`, `database`. Reference: https://api.docs.modulards.com/modular-ds-public-api/malware-scanner/malware-scans/launch-malware-scans ## Authentication - `Authorization` header (bearer token, required) — Personal access token created in the Modular DS dashboard; read-only tokens can only call GET endpoints. ## Request ### Body (application/json) This endpoint expects an object. - `included` (list of string, optional) - `sites` (list of double, optional) ## Response ### 202 202 - Scans launched, two skipped - `data` (list of ApiPublicV1SiteScansPostResponsesContentApplicationJsonSchemaDataItems, optional) - `jsonapi` (ApiPublicV1SiteScansPostResponsesContentApplicationJsonSchemaJsonapi, optional) - `meta` (ApiPublicV1SiteScansPostResponsesContentApplicationJsonSchemaMeta, optional) ## Types ### ApiPublicV1SiteScansPostResponsesContentApplicationJsonSchemaDataItems - `attributes` (ApiPublicV1SiteScansPostResponsesContentApplicationJsonSchemaDataItemsAttributes, optional) - `id` (string, optional) - `links` (ApiPublicV1SiteScansPostResponsesContentApplicationJsonSchemaDataItemsLinks, optional) - `type` (string, optional) ### ApiPublicV1SiteScansPostResponsesContentApplicationJsonSchemaJsonapi - `version` (string, optional) ### ApiPublicV1SiteScansPostResponsesContentApplicationJsonSchemaMeta - `skipped` (list of ApiPublicV1SiteScansPostResponsesContentApplicationJsonSchemaMetaSkippedItems, optional) - `warnings` (list of string, optional) — Names an area left out of a scan that still runs because only some requested areas had quota. ### ApiPublicV1SiteScansPostResponsesContentApplicationJsonSchemaDataItemsAttributes - `comment` (string, optional, nullable) — Note written on the scan; null when there is none. - `created_at` (string, optional) - `db_threats_detected` (integer, optional) — Threats the scan found in the website database. - `files_clean` (integer, optional) — Files the scan found clean. - `files_infected` (integer, optional) — Files the scan found infected. - `files_malicious` (integer, optional) — Files the scan found malicious. - `files_suspicious` (integer, optional) — Files the scan found suspicious. - `has_threats` (boolean, optional) — True when the scan found at least one malicious, suspicious or infected file or one database threat. - `method` (enum, optional) — How the scan started: `manual`, `automatic` for a scheduled one, or `force_first` for the first automatic scan of a website. - Allowed values: `manual`, `automatic`, `force_first` - `omitted` (list of ApiPublicV1SiteScansPostResponsesContentApplicationJsonSchemaDataItemsAttributesOmittedItems, optional) — Parts of the website left out of a scan that still ran because their scan quota was used up; empty when nothing was left out. - `site_id` (integer, optional) — Id of the website that was scanned. - `status` (enum, optional) — Progress of the scan. done and failed are final; quota_exceeded means it could not run because the website had no scan quota left. - Allowed values: `pending`, `in_progress`, `done`, `failed`, `quota_exceeded` - `updated_at` (string, optional) - `verdict` (enum, optional) — The result to read: clean or threats_found once the scan is done, pending or in_progress while it runs, failed or quota_exceeded otherwise. - Allowed values: `pending`, `in_progress`, `clean`, `threats_found`, `failed`, `quota_exceeded` ### ApiPublicV1SiteScansPostResponsesContentApplicationJsonSchemaDataItemsLinks - `self` (string, optional) ### ApiPublicV1SiteScansPostResponsesContentApplicationJsonSchemaMetaSkippedItems - `message` (string, optional) — Human-readable explanation. - `reason_code` (enum, optional) — Why it was refused: PERMISSION_DENIED, SITE_UNREACHABLE, UNSUPPORTED, CONFLICT or QUOTA_EXCEEDED. - Allowed values: `PERMISSION_DENIED`, `SITE_UNREACHABLE`, `UNSUPPORTED`, `CONFLICT`, `QUOTA_EXCEEDED` - `site_id` (integer, optional) — Id of a website that was refused. - `site_name` (string, optional, nullable) — Name of that website; null when the id is outside your token's reach. - `site_scan_id` (integer, optional, nullable) — Always null: a refused website has no scan. ### ApiPublicV1SiteScansPostResponsesContentApplicationJsonSchemaDataItemsAttributesOmittedItems - `branch` (enum, optional) — Part that was left out: files or database. - Allowed values: `files`, `database` - `resets_at` (datetime, optional, nullable) — When the quota of that part refills. ## Examples ### 202 - Scans launched, two skipped **Response** ```json { "data": [ { "attributes": { "comment": null, "created_at": "2026-09-18T11:00:00.000000Z", "db_threats_detected": 0, "files_clean": 0, "files_infected": 0, "files_malicious": 0, "files_suspicious": 0, "has_threats": false, "method": "manual", "omitted": [], "site_id": 101, "status": "pending", "updated_at": "2026-09-18T11:00:00.000000Z", "verdict": "pending" }, "id": "3050", "links": { "self": "https://api.modulards.com/api/public/v1/site-scans/3050" }, "type": "site-scans" } ], "jsonapi": { "version": "1.1" }, "meta": { "skipped": [ { "message": "This website has no malware scans left for the requested areas until 2026-10-01.", "reason_code": "QUOTA_EXCEEDED", "site_id": 102, "site_name": "Acme Blog", "site_scan_id": null }, { "message": "This website has no Malware Scanner configuration; assign one first.", "reason_code": "UNSUPPORTED", "site_id": 103, "site_name": "Beta Shop", "site_scan_id": null } ] } } ``` **SDK Code** ```python 202 - Scans launched, two skipped import requests url = "https://api.modulards.com/api/public/v1/site-scans" headers = {"Authorization": "Bearer "} response = requests.post(url, headers=headers) print(response.json()) ``` ```javascript 202 - Scans launched, two skipped const url = 'https://api.modulards.com/api/public/v1/site-scans'; const options = {method: 'POST', headers: {Authorization: 'Bearer '}}; try { const response = await fetch(url, options); const data = await response.json(); console.log(data); } catch (error) { console.error(error); } ``` ```go 202 - Scans launched, two skipped package main import ( "fmt" "net/http" "io" ) func main() { url := "https://api.modulards.com/api/public/v1/site-scans" req, _ := http.NewRequest("POST", url, nil) req.Header.Add("Authorization", "Bearer ") res, _ := http.DefaultClient.Do(req) defer res.Body.Close() body, _ := io.ReadAll(res.Body) fmt.Println(res) fmt.Println(string(body)) } ``` ```ruby 202 - Scans launched, two skipped require 'uri' require 'net/http' url = URI("https://api.modulards.com/api/public/v1/site-scans") http = Net::HTTP.new(url.host, url.port) http.use_ssl = true request = Net::HTTP::Post.new(url) request["Authorization"] = 'Bearer ' response = http.request(request) puts response.read_body ``` ```java 202 - Scans launched, two skipped import com.mashape.unirest.http.HttpResponse; import com.mashape.unirest.http.Unirest; HttpResponse response = Unirest.post("https://api.modulards.com/api/public/v1/site-scans") .header("Authorization", "Bearer ") .asString(); ``` ```php 202 - Scans launched, two skipped request('POST', 'https://api.modulards.com/api/public/v1/site-scans', [ 'headers' => [ 'Authorization' => 'Bearer ', ], ]); echo $response->getBody(); ``` ```csharp 202 - Scans launched, two skipped using RestSharp; var client = new RestClient("https://api.modulards.com/api/public/v1/site-scans"); var request = new RestRequest(Method.POST); request.AddHeader("Authorization", "Bearer "); IRestResponse response = client.Execute(request); ``` ```swift 202 - Scans launched, two skipped import Foundation let headers = ["Authorization": "Bearer "] let request = NSMutableURLRequest(url: NSURL(string: "https://api.modulards.com/api/public/v1/site-scans")! as URL, cachePolicy: .useProtocolCachePolicy, timeoutInterval: 10.0) request.httpMethod = "POST" request.allHTTPHeaderFields = headers let session = URLSession.shared let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in if (error != nil) { print(error as Any) } else { let httpResponse = response as? HTTPURLResponse print(httpResponse) } }) dataTask.resume() ``` ### Launch malware scans **Request** ```json { "included": [ "core", "database" ], "sites": [ 101, 102, 103 ] } ``` **Response** ```json { "data": [ { "attributes": { "comment": null, "created_at": "2026-09-18T11:00:00.000000Z", "db_threats_detected": 0, "files_clean": 0, "files_infected": 0, "files_malicious": 0, "files_suspicious": 0, "has_threats": false, "method": "manual", "omitted": [], "site_id": 101, "status": "pending", "updated_at": "2026-09-18T11:00:00.000000Z", "verdict": "pending" }, "id": "3050", "links": { "self": "https://api.modulards.com/api/public/v1/site-scans/3050" }, "type": "site-scans" } ], "jsonapi": { "version": "1.1" }, "meta": { "skipped": [ { "message": "This website has no malware scans left for the requested areas until 2026-10-01.", "reason_code": "QUOTA_EXCEEDED", "site_id": 102, "site_name": "Acme Blog", "site_scan_id": null }, { "message": "This website has no Malware Scanner configuration; assign one first.", "reason_code": "UNSUPPORTED", "site_id": 103, "site_name": "Beta Shop", "site_scan_id": null } ] } } ``` **SDK Code** ```python Launch malware scans import requests url = "https://api.modulards.com/api/public/v1/site-scans" payload = { "included": ["core", "database"], "sites": [101, 102, 103] } headers = { "Authorization": "Bearer ", "Content-Type": "application/json" } response = requests.post(url, json=payload, headers=headers) print(response.json()) ``` ```javascript Launch malware scans const url = 'https://api.modulards.com/api/public/v1/site-scans'; const options = { method: 'POST', headers: {Authorization: 'Bearer ', 'Content-Type': 'application/json'}, body: '{"included":["core","database"],"sites":[101,102,103]}' }; try { const response = await fetch(url, options); const data = await response.json(); console.log(data); } catch (error) { console.error(error); } ``` ```go Launch malware scans package main import ( "fmt" "strings" "net/http" "io" ) func main() { url := "https://api.modulards.com/api/public/v1/site-scans" payload := strings.NewReader("{\n \"included\": [\n \"core\",\n \"database\"\n ],\n \"sites\": [\n 101,\n 102,\n 103\n ]\n}") req, _ := http.NewRequest("POST", url, payload) req.Header.Add("Authorization", "Bearer ") req.Header.Add("Content-Type", "application/json") res, _ := http.DefaultClient.Do(req) defer res.Body.Close() body, _ := io.ReadAll(res.Body) fmt.Println(res) fmt.Println(string(body)) } ``` ```ruby Launch malware scans require 'uri' require 'net/http' url = URI("https://api.modulards.com/api/public/v1/site-scans") http = Net::HTTP.new(url.host, url.port) http.use_ssl = true request = Net::HTTP::Post.new(url) request["Authorization"] = 'Bearer ' request["Content-Type"] = 'application/json' request.body = "{\n \"included\": [\n \"core\",\n \"database\"\n ],\n \"sites\": [\n 101,\n 102,\n 103\n ]\n}" response = http.request(request) puts response.read_body ``` ```java Launch malware scans import com.mashape.unirest.http.HttpResponse; import com.mashape.unirest.http.Unirest; HttpResponse response = Unirest.post("https://api.modulards.com/api/public/v1/site-scans") .header("Authorization", "Bearer ") .header("Content-Type", "application/json") .body("{\n \"included\": [\n \"core\",\n \"database\"\n ],\n \"sites\": [\n 101,\n 102,\n 103\n ]\n}") .asString(); ``` ```php Launch malware scans request('POST', 'https://api.modulards.com/api/public/v1/site-scans', [ 'body' => '{ "included": [ "core", "database" ], "sites": [ 101, 102, 103 ] }', 'headers' => [ 'Authorization' => 'Bearer ', 'Content-Type' => 'application/json', ], ]); echo $response->getBody(); ``` ```csharp Launch malware scans using RestSharp; var client = new RestClient("https://api.modulards.com/api/public/v1/site-scans"); var request = new RestRequest(Method.POST); request.AddHeader("Authorization", "Bearer "); request.AddHeader("Content-Type", "application/json"); request.AddParameter("application/json", "{\n \"included\": [\n \"core\",\n \"database\"\n ],\n \"sites\": [\n 101,\n 102,\n 103\n ]\n}", ParameterType.RequestBody); IRestResponse response = client.Execute(request); ``` ```swift Launch malware scans import Foundation let headers = [ "Authorization": "Bearer ", "Content-Type": "application/json" ] let parameters = [ "included": ["core", "database"], "sites": [101, 102, 103] ] as [String : Any] let postData = JSONSerialization.data(withJSONObject: parameters, options: []) let request = NSMutableURLRequest(url: NSURL(string: "https://api.modulards.com/api/public/v1/site-scans")! as URL, cachePolicy: .useProtocolCachePolicy, timeoutInterval: 10.0) request.httpMethod = "POST" request.allHTTPHeaderFields = headers request.httpBody = postData as Data let session = URLSession.shared let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in if (error != nil) { print(error as Any) } else { let httpResponse = response as? HTTPURLResponse print(httpResponse) } }) dataTask.resume() ```