> For clean Markdown of any page, append .md to the page URL. > For a complete documentation index, see https://api.docs.modulards.com/modular-ds-public-api/malware-scanner/malware-scans/update-a-malware-scan-s-comment/llms.txt. > For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://api.docs.modulards.com/_mcp/server. # Update a malware scan's comment PATCH https://api.modulards.com/api/public/v1/site-scans/{site_scan} Content-Type: application/json Writes the comment of one malware scan, replacing whatever it held: use it to record what you found. Nothing else about the scan changes: to launch a new scan use "Launch malware scans". **Body** - `comment` (string or `null`, optional): at most 2500 bytes once HTML tags are stripped (a character outside plain ASCII counts as more than one byte). Send `null` or omit it to clear the comment. **Errors** - **422**: the comment is not a string or is too long. Reference: https://api.docs.modulards.com/modular-ds-public-api/malware-scanner/malware-scans/update-a-malware-scan-s-comment ## Authentication - `Authorization` header (bearer token, required) — Personal access token created in the Modular DS dashboard; read-only tokens can only call GET endpoints. ## Request ### Path parameters - `site_scan` (string, required) ### Body (application/json) This endpoint expects an object. - `comment` (string, optional) ## Response ### 200 200 - Site scan comment updated - `data` (ApiPublicV1SiteScansSiteScanPatchResponsesContentApplicationJsonSchemaData, optional) - `jsonapi` (ApiPublicV1SiteScansSiteScanPatchResponsesContentApplicationJsonSchemaJsonapi, optional) ## Types ### ApiPublicV1SiteScansSiteScanPatchResponsesContentApplicationJsonSchemaData - `attributes` (ApiPublicV1SiteScansSiteScanPatchResponsesContentApplicationJsonSchemaDataAttributes, optional) - `id` (string, optional) - `links` (ApiPublicV1SiteScansSiteScanPatchResponsesContentApplicationJsonSchemaDataLinks, optional) - `type` (string, optional) ### ApiPublicV1SiteScansSiteScanPatchResponsesContentApplicationJsonSchemaJsonapi - `version` (string, optional) ### ApiPublicV1SiteScansSiteScanPatchResponsesContentApplicationJsonSchemaDataAttributes - `comment` (string, optional, nullable) — Note written on the scan; null when there is none. - `created_at` (string, optional) - `db_threats_detected` (integer, optional) — Threats the scan found in the website database. - `files_clean` (integer, optional) — Files the scan found clean. - `files_infected` (integer, optional) — Files the scan found infected. - `files_malicious` (integer, optional) — Files the scan found malicious. - `files_suspicious` (integer, optional) — Files the scan found suspicious. - `has_threats` (boolean, optional) — True when the scan found at least one malicious, suspicious or infected file or one database threat. - `method` (enum, optional) — How the scan started: `manual`, `automatic` for a scheduled one, or `force_first` for the first automatic scan of a website. - Allowed values: `manual`, `automatic`, `force_first` - `omitted` (list of ApiPublicV1SiteScansSiteScanPatchResponsesContentApplicationJsonSchemaDataAttributesOmittedItems, optional) — Parts of the website left out of a scan that still ran because their scan quota was used up; empty when nothing was left out. - `site_id` (integer, optional) — Id of the website that was scanned. - `status` (enum, optional) — Progress of the scan. done and failed are final; quota_exceeded means it could not run because the website had no scan quota left. - Allowed values: `pending`, `in_progress`, `done`, `failed`, `quota_exceeded` - `updated_at` (string, optional) - `verdict` (enum, optional) — The result to read: clean or threats_found once the scan is done, pending or in_progress while it runs, failed or quota_exceeded otherwise. - Allowed values: `pending`, `in_progress`, `clean`, `threats_found`, `failed`, `quota_exceeded` ### ApiPublicV1SiteScansSiteScanPatchResponsesContentApplicationJsonSchemaDataLinks - `self` (string, optional) ### ApiPublicV1SiteScansSiteScanPatchResponsesContentApplicationJsonSchemaDataAttributesOmittedItems - `branch` (enum, optional) — Part that was left out: files or database. - Allowed values: `files`, `database` - `resets_at` (datetime, optional, nullable) — When the quota of that part refills. ## Examples ### 200 - Site scan comment updated **Response** ```json { "data": { "attributes": { "comment": "False positive, confirmed by the plugin author.", "created_at": "2026-09-18T09:00:00.000000Z", "db_threats_detected": 0, "files_clean": 4198, "files_infected": 9, "files_malicious": 2, "files_suspicious": 1, "has_threats": true, "method": "manual", "omitted": [], "site_id": 101, "status": "done", "updated_at": "2026-09-18T11:20:00.000000Z", "verdict": "threats_found" }, "id": "3021", "links": { "self": "https://api.modulards.com/api/public/v1/site-scans/3021" }, "type": "site-scans" }, "jsonapi": { "version": "1.1" } } ``` **SDK Code** ```python 200 - Site scan comment updated import requests url = "https://api.modulards.com/api/public/v1/site-scans/site_scan" headers = {"Authorization": "Bearer "} response = requests.patch(url, headers=headers) print(response.json()) ``` ```javascript 200 - Site scan comment updated const url = 'https://api.modulards.com/api/public/v1/site-scans/site_scan'; const options = {method: 'PATCH', headers: {Authorization: 'Bearer '}}; try { const response = await fetch(url, options); const data = await response.json(); console.log(data); } catch (error) { console.error(error); } ``` ```go 200 - Site scan comment updated package main import ( "fmt" "net/http" "io" ) func main() { url := "https://api.modulards.com/api/public/v1/site-scans/site_scan" req, _ := http.NewRequest("PATCH", url, nil) req.Header.Add("Authorization", "Bearer ") res, _ := http.DefaultClient.Do(req) defer res.Body.Close() body, _ := io.ReadAll(res.Body) fmt.Println(res) fmt.Println(string(body)) } ``` ```ruby 200 - Site scan comment updated require 'uri' require 'net/http' url = URI("https://api.modulards.com/api/public/v1/site-scans/site_scan") http = Net::HTTP.new(url.host, url.port) http.use_ssl = true request = Net::HTTP::Patch.new(url) request["Authorization"] = 'Bearer ' response = http.request(request) puts response.read_body ``` ```java 200 - Site scan comment updated import com.mashape.unirest.http.HttpResponse; import com.mashape.unirest.http.Unirest; HttpResponse response = Unirest.patch("https://api.modulards.com/api/public/v1/site-scans/site_scan") .header("Authorization", "Bearer ") .asString(); ``` ```php 200 - Site scan comment updated request('PATCH', 'https://api.modulards.com/api/public/v1/site-scans/site_scan', [ 'headers' => [ 'Authorization' => 'Bearer ', ], ]); echo $response->getBody(); ``` ```csharp 200 - Site scan comment updated using RestSharp; var client = new RestClient("https://api.modulards.com/api/public/v1/site-scans/site_scan"); var request = new RestRequest(Method.PATCH); request.AddHeader("Authorization", "Bearer "); IRestResponse response = client.Execute(request); ``` ```swift 200 - Site scan comment updated import Foundation let headers = ["Authorization": "Bearer "] let request = NSMutableURLRequest(url: NSURL(string: "https://api.modulards.com/api/public/v1/site-scans/site_scan")! as URL, cachePolicy: .useProtocolCachePolicy, timeoutInterval: 10.0) request.httpMethod = "PATCH" request.allHTTPHeaderFields = headers let session = URLSession.shared let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in if (error != nil) { print(error as Any) } else { let httpResponse = response as? HTTPURLResponse print(httpResponse) } }) dataTask.resume() ``` ### Update a malware scan's comment **Request** ```json { "comment": "False positive, confirmed by the plugin author." } ``` **Response** ```json { "data": { "attributes": { "comment": "False positive, confirmed by the plugin author.", "created_at": "2026-09-18T09:00:00.000000Z", "db_threats_detected": 0, "files_clean": 4198, "files_infected": 9, "files_malicious": 2, "files_suspicious": 1, "has_threats": true, "method": "manual", "omitted": [], "site_id": 101, "status": "done", "updated_at": "2026-09-18T11:20:00.000000Z", "verdict": "threats_found" }, "id": "3021", "links": { "self": "https://api.modulards.com/api/public/v1/site-scans/3021" }, "type": "site-scans" }, "jsonapi": { "version": "1.1" } } ``` **SDK Code** ```python Update a malware scan's comment import requests url = "https://api.modulards.com/api/public/v1/site-scans/site_scan" payload = { "comment": "False positive, confirmed by the plugin author." } headers = { "Authorization": "Bearer ", "Content-Type": "application/json" } response = requests.patch(url, json=payload, headers=headers) print(response.json()) ``` ```javascript Update a malware scan's comment const url = 'https://api.modulards.com/api/public/v1/site-scans/site_scan'; const options = { method: 'PATCH', headers: {Authorization: 'Bearer ', 'Content-Type': 'application/json'}, body: '{"comment":"False positive, confirmed by the plugin author."}' }; try { const response = await fetch(url, options); const data = await response.json(); console.log(data); } catch (error) { console.error(error); } ``` ```go Update a malware scan's comment package main import ( "fmt" "strings" "net/http" "io" ) func main() { url := "https://api.modulards.com/api/public/v1/site-scans/site_scan" payload := strings.NewReader("{\n \"comment\": \"False positive, confirmed by the plugin author.\"\n}") req, _ := http.NewRequest("PATCH", url, payload) req.Header.Add("Authorization", "Bearer ") req.Header.Add("Content-Type", "application/json") res, _ := http.DefaultClient.Do(req) defer res.Body.Close() body, _ := io.ReadAll(res.Body) fmt.Println(res) fmt.Println(string(body)) } ``` ```ruby Update a malware scan's comment require 'uri' require 'net/http' url = URI("https://api.modulards.com/api/public/v1/site-scans/site_scan") http = Net::HTTP.new(url.host, url.port) http.use_ssl = true request = Net::HTTP::Patch.new(url) request["Authorization"] = 'Bearer ' request["Content-Type"] = 'application/json' request.body = "{\n \"comment\": \"False positive, confirmed by the plugin author.\"\n}" response = http.request(request) puts response.read_body ``` ```java Update a malware scan's comment import com.mashape.unirest.http.HttpResponse; import com.mashape.unirest.http.Unirest; HttpResponse response = Unirest.patch("https://api.modulards.com/api/public/v1/site-scans/site_scan") .header("Authorization", "Bearer ") .header("Content-Type", "application/json") .body("{\n \"comment\": \"False positive, confirmed by the plugin author.\"\n}") .asString(); ``` ```php Update a malware scan's comment request('PATCH', 'https://api.modulards.com/api/public/v1/site-scans/site_scan', [ 'body' => '{ "comment": "False positive, confirmed by the plugin author." }', 'headers' => [ 'Authorization' => 'Bearer ', 'Content-Type' => 'application/json', ], ]); echo $response->getBody(); ``` ```csharp Update a malware scan's comment using RestSharp; var client = new RestClient("https://api.modulards.com/api/public/v1/site-scans/site_scan"); var request = new RestRequest(Method.PATCH); request.AddHeader("Authorization", "Bearer "); request.AddHeader("Content-Type", "application/json"); request.AddParameter("application/json", "{\n \"comment\": \"False positive, confirmed by the plugin author.\"\n}", ParameterType.RequestBody); IRestResponse response = client.Execute(request); ``` ```swift Update a malware scan's comment import Foundation let headers = [ "Authorization": "Bearer ", "Content-Type": "application/json" ] let parameters = ["comment": "False positive, confirmed by the plugin author."] as [String : Any] let postData = JSONSerialization.data(withJSONObject: parameters, options: []) let request = NSMutableURLRequest(url: NSURL(string: "https://api.modulards.com/api/public/v1/site-scans/site_scan")! as URL, cachePolicy: .useProtocolCachePolicy, timeoutInterval: 10.0) request.httpMethod = "PATCH" request.allHTTPHeaderFields = headers request.httpBody = postData as Data let session = URLSession.shared let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in if (error != nil) { print(error as Any) } else { let httpResponse = response as? HTTPURLResponse print(httpResponse) } }) dataTask.resume() ```