Skip to main content
Drupal is a registered trademark of Dries Buytaert
Release: OpenID Connect / OAuth client 3.0.0-alpha9 New alpha version released for module openid_connect (3.0.0-alpha9). Usage Milestone: Google Analytics Module google_analytics crossed 1,000 active installs. Release: Timelinr 1.0.1 Minor update available for module timelinr (1.0.1). Release: GraphQL Compose Codegen 1.1.2 Minor update available for module graphql_compose_codegen (1.1.2). Release: Mapy.com 1.1.3 Minor update available for module mapycom (1.1.3). Release: Ckeditor5 entity browser 3.0.3 Minor update available for module ckeditor5_entity_browser (3.0.3). Release: Ckeditor5 entity browser 3.0.1 Minor update available for module ckeditor5_entity_browser (3.0.1). Release: Ckeditor5 entity browser 3.0.2 Minor update available for module ckeditor5_entity_browser (3.0.2). Release: Teamleader Integration 4.0.2 Minor update available for module teamleader (4.0.2). Module Revived: Entityqueue Buttons 1.1.2 Module entityqueue_buttons updated after 8 months of inactivity (1.1.2).

HTTP Anti-virus

54 sites Security covered Drupal 8–11
View on drupal.org

This module sends uploaded files to a configurable HTTP service for validation. The service's response determines whether Drupal accepts the file, offering a way to integrate antivirus scanning with a standard web interface.

A Drupal module that submits uploaded files to a HTTP service endpoint. Uploaded files are sent in a configurable manner to a configurable endpoint. The response of which will control if the file can be accepted by Drupal.

The intent is to obfuscate complicated TCP/Sock Anti-virus backends with a standard HTTP interface to allow for a more microservice architecture.

Prerequisites

  1. A service that is reachable via HTTP

API requirements

The module makes some assumptions on how the HTTP request needs to be made. It allows for parts of the request to be configurable to help accommodate differences in service endpoints.

Request

The module will make a request that looks like:

'Headers' => {
  'Content-Type' => 'multipart/form-data'
}
'multipart' => [
  [
    'name' => 'malware',
    'contents' => '@file.png',
    'filename' => 'file.png',
  ]
]

Response

The module assumes that the service will respond with the results in a particular format.

{
  "result": {
    "infected":true,
    "result":"ApplicUnwnt",
    "engine":"5.0.163652.1142",
    "updated":"20190406"
  }
}

The module expects the service to return with the `infected` key to represent if the file can be saved or not. If the `infected` key is `true` the file will fail the validation check in Drupal and will not allow the file to be saved.

Similar projects

  • ClamAV: Anti-virus backend for media management.

Depends on

Dependencies of the latest stable release

No dependencies recorded for this project.

Required by

Tracked projects that depend on this one

No tracked projects depend on this one yet.

Activity

Tracked releases
8
Tracked since
Feb 2025
Latest release
1 month ago
Releases (12 mo)
7 ▲ from 1
Maintenance
Active

Release Timeline

Releases

Version Type Core Release date
1.1.5 Stable 8–11 Jul 21, 2026
1.3.3 Stable 10–11 Jul 21, 2026
1.1.4 Stable 8–11 Jul 14, 2026
1.3.2 Stable 10–11 Jul 14, 2026
1.1.3 Stable 8–11 May 14, 2026
1.3.1 Stable 10–11 May 14, 2026
1.3.0 Stable 10–11 Feb 10, 2026
1.2.0 Stable 8–11 Feb 24, 2025