> For clean Markdown of any page, append .md to the page URL. > For a complete documentation index, see https://api.docs.modulards.com/modular-ds-public-api/malware-scanner/malware-scans/list-malware-scans/llms.txt. > For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://api.docs.modulards.com/_mcp/server. # List malware scans GET https://api.modulards.com/api/public/v1/site-scans Lists the malware scans of every website your token can reach, newest first. Use `filter[site][]` for the scans of one or several websites, or `filter[id][]` to follow the scans a launch started. A scan can take hours: read `verdict` (`pending` and `in_progress` mean it is still running; `clean`, `threats_found`, `failed` and `quota_exceeded` are final). `omitted` lists the areas skipped for lack of scan quota, with their reset dates. Reference: https://api.docs.modulards.com/modular-ds-public-api/malware-scanner/malware-scans/list-malware-scans ## Authentication - `Authorization` header (bearer token, required) — Personal access token created in the Modular DS dashboard; read-only tokens can only call GET endpoints. ## Request ### Query parameters - `filter[site][]` (string, optional) — Exact website ids. Repeat the parameter for several: any of them matches. - `filter[id][]` (string, optional) — Exact scan ids, for example to follow a launched batch. Repeat the parameter for several. - `filter[status][]` (string, optional) — `pending`, `in_progress`, `done`, `failed` or `quota_exceeded`. Repeat the parameter for several. - `filter[verdict][]` (string, optional) — `pending`, `in_progress`, `clean`, `threats_found`, `failed` or `quota_exceeded`. Repeat the parameter for several. - `filter[method][]` (string, optional) — How the scan started: `manual`, `automatic` for a scheduled one, or `force_first` for the first automatic scan of a website. Repeat the parameter for several: any of them matches. - `sort` (string, optional) — `created_at` or `updated_at`; prefix with `-` for descending. Default: `-created_at` (newest first). - `page[number]` (string, optional) — Page number, starting at 1. Default 1. - `page[size]` (string, optional) — Items per page, 1 to 50. Default 15. - `include` (string, optional) — Relations to add to the answer: `site` (the website). ## Response ### 200 200 - Site scans list - `data` (list of ApiPublicV1SiteScansGetResponsesContentApplicationJsonSchemaDataItems, optional) - `jsonapi` (ApiPublicV1SiteScansGetResponsesContentApplicationJsonSchemaJsonapi, optional) - `links` (ApiPublicV1SiteScansGetResponsesContentApplicationJsonSchemaLinks, optional) - `meta` (ApiPublicV1SiteScansGetResponsesContentApplicationJsonSchemaMeta, optional) ## Types ### ApiPublicV1SiteScansGetResponsesContentApplicationJsonSchemaDataItems - `attributes` (ApiPublicV1SiteScansGetResponsesContentApplicationJsonSchemaDataItemsAttributes, optional) - `id` (string, optional) - `links` (ApiPublicV1SiteScansGetResponsesContentApplicationJsonSchemaDataItemsLinks, optional) - `type` (string, optional) ### ApiPublicV1SiteScansGetResponsesContentApplicationJsonSchemaJsonapi - `version` (string, optional) ### ApiPublicV1SiteScansGetResponsesContentApplicationJsonSchemaLinks - `first` (string, optional) - `last` (string, optional) - `next` (any, optional, nullable) - `prev` (any, optional, nullable) ### ApiPublicV1SiteScansGetResponsesContentApplicationJsonSchemaMeta - `current_page` (double, optional) - `from` (double, optional) - `last_page` (double, optional) - `links` (list of ApiPublicV1SiteScansGetResponsesContentApplicationJsonSchemaMetaLinksItems, optional) - `path` (string, optional) - `per_page` (double, optional) - `to` (double, optional) - `total` (double, optional) ### ApiPublicV1SiteScansGetResponsesContentApplicationJsonSchemaDataItemsAttributes - `comment` (string, optional, nullable) — Note written on the scan; null when there is none. - `created_at` (string, optional) - `db_threats_detected` (integer, optional) — Threats the scan found in the website database. - `files_clean` (integer, optional) — Files the scan found clean. - `files_infected` (integer, optional) — Files the scan found infected. - `files_malicious` (integer, optional) — Files the scan found malicious. - `files_suspicious` (integer, optional) — Files the scan found suspicious. - `has_threats` (boolean, optional) — True when the scan found at least one malicious, suspicious or infected file or one database threat. - `method` (enum, optional) — How the scan started: `manual`, `automatic` for a scheduled one, or `force_first` for the first automatic scan of a website. - Allowed values: `manual`, `automatic`, `force_first` - `omitted` (list of ApiPublicV1SiteScansGetResponsesContentApplicationJsonSchemaDataItemsAttributesOmittedItems, optional) — Parts of the website left out of a scan that still ran because their scan quota was used up; empty when nothing was left out. - `site_id` (integer, optional) — Id of the website that was scanned. - `status` (enum, optional) — Progress of the scan. done and failed are final; quota_exceeded means it could not run because the website had no scan quota left. - Allowed values: `pending`, `in_progress`, `done`, `failed`, `quota_exceeded` - `updated_at` (string, optional) - `verdict` (enum, optional) — The result to read: clean or threats_found once the scan is done, pending or in_progress while it runs, failed or quota_exceeded otherwise. - Allowed values: `pending`, `in_progress`, `clean`, `threats_found`, `failed`, `quota_exceeded` ### ApiPublicV1SiteScansGetResponsesContentApplicationJsonSchemaDataItemsLinks - `self` (string, optional) ### ApiPublicV1SiteScansGetResponsesContentApplicationJsonSchemaMetaLinksItems - `active` (boolean, optional) - `label` (string, optional) - `url` (string, optional, nullable) ### ApiPublicV1SiteScansGetResponsesContentApplicationJsonSchemaDataItemsAttributesOmittedItems - `branch` (enum, optional) — Part that was left out: files or database. - Allowed values: `files`, `database` - `resets_at` (datetime, optional, nullable) — When the quota of that part refills. ## Examples **Response** ```json { "data": [ { "attributes": { "comment": null, "created_at": "2026-09-18T09:00:00.000000Z", "db_threats_detected": 0, "files_clean": 4210, "files_infected": 0, "files_malicious": 0, "files_suspicious": 0, "has_threats": false, "method": "manual", "omitted": [], "site_id": 101, "status": "done", "updated_at": "2026-09-18T09:14:00.000000Z", "verdict": "clean" }, "id": "3021", "links": { "self": "https://api.modulards.com/api/public/v1/site-scans/3021" }, "type": "site-scans" } ], "jsonapi": { "version": "1.1" }, "links": { "first": "{{base_url}}/api/public/v1/site-scans?page%5Bnumber%5D=1", "last": "{{base_url}}/api/public/v1/site-scans?page%5Bnumber%5D=1", "next": null, "prev": null }, "meta": { "current_page": 1, "from": 1, "last_page": 1, "links": [ { "active": false, "label": "« Previous", "url": null }, { "active": true, "label": "1", "url": "{{base_url}}/api/public/v1/site-scans?page%5Bnumber%5D=1" }, { "active": false, "label": "Next »", "url": null } ], "path": "{{base_url}}/api/public/v1/site-scans", "per_page": 15, "to": 1, "total": 1 } } ``` **SDK Code** ```python 200 - Site scans list import requests url = "https://api.modulards.com/api/public/v1/site-scans" headers = {"Authorization": "Bearer "} response = requests.get(url, headers=headers) print(response.json()) ``` ```javascript 200 - Site scans list const url = 'https://api.modulards.com/api/public/v1/site-scans'; const options = {method: 'GET', headers: {Authorization: 'Bearer '}}; try { const response = await fetch(url, options); const data = await response.json(); console.log(data); } catch (error) { console.error(error); } ``` ```go 200 - Site scans list package main import ( "fmt" "net/http" "io" ) func main() { url := "https://api.modulards.com/api/public/v1/site-scans" req, _ := http.NewRequest("GET", url, nil) req.Header.Add("Authorization", "Bearer ") res, _ := http.DefaultClient.Do(req) defer res.Body.Close() body, _ := io.ReadAll(res.Body) fmt.Println(res) fmt.Println(string(body)) } ``` ```ruby 200 - Site scans list require 'uri' require 'net/http' url = URI("https://api.modulards.com/api/public/v1/site-scans") http = Net::HTTP.new(url.host, url.port) http.use_ssl = true request = Net::HTTP::Get.new(url) request["Authorization"] = 'Bearer ' response = http.request(request) puts response.read_body ``` ```java 200 - Site scans list import com.mashape.unirest.http.HttpResponse; import com.mashape.unirest.http.Unirest; HttpResponse response = Unirest.get("https://api.modulards.com/api/public/v1/site-scans") .header("Authorization", "Bearer ") .asString(); ``` ```php 200 - Site scans list request('GET', 'https://api.modulards.com/api/public/v1/site-scans', [ 'headers' => [ 'Authorization' => 'Bearer ', ], ]); echo $response->getBody(); ``` ```csharp 200 - Site scans list using RestSharp; var client = new RestClient("https://api.modulards.com/api/public/v1/site-scans"); var request = new RestRequest(Method.GET); request.AddHeader("Authorization", "Bearer "); IRestResponse response = client.Execute(request); ``` ```swift 200 - Site scans list import Foundation let headers = ["Authorization": "Bearer "] let request = NSMutableURLRequest(url: NSURL(string: "https://api.modulards.com/api/public/v1/site-scans")! as URL, cachePolicy: .useProtocolCachePolicy, timeoutInterval: 10.0) request.httpMethod = "GET" request.allHTTPHeaderFields = headers let session = URLSession.shared let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in if (error != nil) { print(error as Any) } else { let httpResponse = response as? HTTPURLResponse print(httpResponse) } }) dataTask.resume() ```