{"adoption": {"forks": 277, "observed_at": "2026-08-28T04:04:49.769394+00:00", "stars": 1475}, "canonical_url": "https://ross.abutalabs.com/products/php-malware-finder", "card": {"archived": true, "artifact_type": "cli-tool", "description": "Detect potentially malicious PHP files", "domain": ["security", "web-development", "developer-tools"], "enriched": true, "function": ["security", "vulnerability-scanning", "search-engine"], "health_score": 10, "homepage": null, "language": "PHP", "license": "LGPL-3.0", "license_family": "copyleft", "maturity": "active", "member_repos": ["jvoisin/php-malware-finder"], "name": "jvoisin/php-malware-finder", "platform": ["cli", "cross-platform"], "pushed_at": "2023-10-20T16:02:54+00:00", "repo": "jvoisin/php-malware-finder", "stars": 1475, "tags": ["yara", "webshell-detection", "php-malware", "antivirus", "obfuscation-detection", "linux", "macos"], "topics": ["yara", "php", "malware", "webshell", "antivirus"], "urls": [], "use_cases": ["scan a web server for uploaded webshells", "detect obfuscated PHP malware in a codebase", "clean up a compromised website", "audit PHP files for suspicious function usage", "find backdoors planted by attackers in a CMS", "hunt for known webshell families like Weevely3 or novahot"], "what_it_is": "PHP Malware Finder is a command-line tool that scans filesystems for potentially malicious PHP files using YARA rules. It detects obfuscated code, webshells, and common malware patterns through semantic analysis rather than hash matching.", "when_to_avoid": ["you need guaranteed protection against sophisticated, tailored malware (the tool is explicitly bypassable)", "you need runtime protection rather than on-disk file scanning", "your stack is not PHP-based"], "when_to_choose": ["you need to triage a potentially compromised PHP web server", "you want semantic detection that catches obfuscated and mutated malware, not just known hashes", "you want a simple, fast filesystem scanner with YARA rules you can extend"]}, "data_as_of": "2026-08-30T08:39:29.467469+00:00", "members": [{"path": "/products/php-malware-finder", "repo": "jvoisin/php-malware-finder", "role": "main", "score": 10}], "provenance": {"archived": {"kind": "observed", "observed_at": "2026-08-28T04:04:49.769394+00:00", "source": "github"}, "artifact_type": {"confidence": null, "enriched_at": "2026-08-30T04:34:31.228806+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "7a8750baed9aa47e4f7d5f60da3ab3ff449280795bdb60f92926afef2a26f118", "fetched_at": "2026-08-28T04:04:49.769394+00:00", "kind": "readme", "missing": false, "url": "https://github.com/jvoisin/php-malware-finder"}], "taxonomy_version": 1}, "description": {"kind": "observed", "observed_at": "2026-08-28T04:04:49.769394+00:00", "source": "github"}, "domain": {"confidence": null, "enriched_at": "2026-08-30T04:34:31.228806+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "7a8750baed9aa47e4f7d5f60da3ab3ff449280795bdb60f92926afef2a26f118", "fetched_at": "2026-08-28T04:04:49.769394+00:00", "kind": "readme", "missing": false, "url": "https://github.com/jvoisin/php-malware-finder"}], "taxonomy_version": 1}, "enriched": {"inputs": [], "kind": "computed", "method": "enrichment_status"}, "function": {"confidence": null, "enriched_at": "2026-08-30T04:34:31.228806+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "7a8750baed9aa47e4f7d5f60da3ab3ff449280795bdb60f92926afef2a26f118", "fetched_at": "2026-08-28T04:04:49.769394+00:00", "kind": "readme", "missing": false, "url": "https://github.com/jvoisin/php-malware-finder"}], "taxonomy_version": 1}, "health_score": {"inputs": ["days_since_push", "days_since_release", "archived"], "kind": "computed", "method": "health_v1"}, "homepage": {"kind": "observed", "observed_at": "2026-08-28T04:04:49.769394+00:00", "source": "github"}, "language": {"kind": "observed", "observed_at": "2026-08-28T04:04:49.769394+00:00", "source": "github"}, "license": {"kind": "observed", "observed_at": "2026-08-28T04:04:49.769394+00:00", "source": "github"}, "license_family": {"inputs": ["license"], "kind": "computed", "method": "license_family"}, "maturity": {"confidence": null, "enriched_at": "2026-08-30T04:34:31.228806+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "7a8750baed9aa47e4f7d5f60da3ab3ff449280795bdb60f92926afef2a26f118", "fetched_at": "2026-08-28T04:04:49.769394+00:00", "kind": "readme", "missing": false, "url": "https://github.com/jvoisin/php-malware-finder"}], "taxonomy_version": 1}, "member_repos": {"kind": "observed", "observed_at": "2026-08-28T04:04:49.769394+00:00", "source": "github"}, "name": {"kind": "observed", "observed_at": "2026-08-28T04:04:49.769394+00:00", "source": "github"}, "platform": {"confidence": null, "enriched_at": "2026-08-30T04:34:31.228806+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "7a8750baed9aa47e4f7d5f60da3ab3ff449280795bdb60f92926afef2a26f118", "fetched_at": "2026-08-28T04:04:49.769394+00:00", "kind": "readme", "missing": false, "url": "https://github.com/jvoisin/php-malware-finder"}], "taxonomy_version": 1}, "pushed_at": {"kind": "observed", "observed_at": "2026-08-28T04:04:49.769394+00:00", "source": "github"}, "repo": {"kind": "observed", "observed_at": "2026-08-28T04:04:49.769394+00:00", "source": "github"}, "stars": {"kind": "observed", "observed_at": "2026-08-28T04:04:49.769394+00:00", "source": "github"}, "tags": {"confidence": null, "enriched_at": "2026-08-30T04:34:31.228806+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "7a8750baed9aa47e4f7d5f60da3ab3ff449280795bdb60f92926afef2a26f118", "fetched_at": "2026-08-28T04:04:49.769394+00:00", "kind": "readme", "missing": false, "url": "https://github.com/jvoisin/php-malware-finder"}], "taxonomy_version": 1}, "topics": {"kind": "observed", "observed_at": "2026-08-28T04:04:49.769394+00:00", "source": "github"}, "urls": {"kind": "observed", "observed_at": "2026-08-28T04:04:49.769394+00:00", "source": "github"}, "use_cases": {"confidence": null, "enriched_at": "2026-08-30T04:34:31.228806+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "7a8750baed9aa47e4f7d5f60da3ab3ff449280795bdb60f92926afef2a26f118", "fetched_at": "2026-08-28T04:04:49.769394+00:00", "kind": "readme", "missing": false, "url": "https://github.com/jvoisin/php-malware-finder"}], "taxonomy_version": 1}, "what_it_is": {"confidence": null, "enriched_at": "2026-08-30T04:34:31.228806+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "7a8750baed9aa47e4f7d5f60da3ab3ff449280795bdb60f92926afef2a26f118", "fetched_at": "2026-08-28T04:04:49.769394+00:00", "kind": "readme", "missing": false, "url": "https://github.com/jvoisin/php-malware-finder"}], "taxonomy_version": 1}, "when_to_avoid": {"confidence": null, "enriched_at": "2026-08-30T04:34:31.228806+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "7a8750baed9aa47e4f7d5f60da3ab3ff449280795bdb60f92926afef2a26f118", "fetched_at": "2026-08-28T04:04:49.769394+00:00", "kind": "readme", "missing": false, "url": "https://github.com/jvoisin/php-malware-finder"}], "taxonomy_version": 1}, "when_to_choose": {"confidence": null, "enriched_at": "2026-08-30T04:34:31.228806+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "7a8750baed9aa47e4f7d5f60da3ab3ff449280795bdb60f92926afef2a26f118", "fetched_at": "2026-08-28T04:04:49.769394+00:00", "kind": "readme", "missing": false, "url": "https://github.com/jvoisin/php-malware-finder"}], "taxonomy_version": 1}}, "score": {"components": {"activity": 0, "longevity": 100, "rhythm": 8}, "computed_at": "2026-09-02T17:46:02.011165+00:00", "flags": ["archived"], "formula": "round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)", "inputs": {"age_days": 4080, "days_push": 1048, "days_rel": null, "gap_med": null, "n_releases_24m": 0}, "score": 10, "version": 2}, "staleness": {"enrichment_outdated": false, "low_confidence": false, "scrape_days": 9, "stale_scrape": false}}