Looking to hire Laravel developers? Try LaraJobs

cypherscan-laravelplus-driver maintained by cyphernetsecurity

Description
CypherScan malware scanner driver for LaravelPlus Content Security.
Last update
2026/09/16 03:38 (dev-main)
License
Links
Downloads
0

Comments
comments powered by Disqus

CypherScan Driver for LaravelPlus Content Security

Standalone CypherScan malware scanner driver for laravelplus/content-security.

Requirements

  • PHP 8.5+
  • Laravel 13
  • laravelplus/content-security 1.x
  • A CypherScan API key

Installation

Once the package is available through Packagist:

composer require cyphernetsecurity/cypherscan-laravelplus-driver

Until then, the source repository can be used as a Composer VCS repository.

Configuration

Create a CypherScan API key and configure the host application:

CYPHERSCAN_API_KEY=cs_your_key
CYPHERSCAN_BASE_URL=https://cyphernetsecurity.com
CONTENT_SECURITY_MALWARE_DRIVER=cypherscan

Add the driver under content-security.malware.drivers:

'cypherscan' => [
    'driver' => 'cypherscan',
],

Laravel package discovery registers CypherScanServiceProvider automatically.

Security behavior

The integration is fail-closed:

  • clean maps to LaravelPlus Clean
  • suspicious maps to Suspicious
  • malicious maps to Infected
  • unavailable scanners, invalid responses, unknown verdicts, and unusable upload responses do not pass content as clean
  • the SHA-256 returned by CypherScan must match the exact LaravelPlus FileReference::checksum() before a verdict is accepted

API flow

The driver uses CypherScan's canonical authenticated file workflow:

  1. POST /api/v1/upload/presign
  2. upload the exact file bytes to the returned temporary URL
  3. POST /api/v1/scan with the returned object key
  4. map the verified CypherScan verdict into a LaravelPlus CheckResult

Testing

composer test

The package includes contract coverage for clean, suspicious, malicious, fail-closed conditions, health reporting, SHA-256 binding, and LaravelPlus driver registration.

License

MIT