Updating Definitions & Scanner
Use the update method that matches the installation method.
Automatic definition updates
Each scan checks the versioned AMWScan bundle and Maltrail domain data on GitHub. AMWScan stages changed signature, exploit, and hash files under the private --path-definitions directory and activates them only after manifest, size, checksum, schema, regex, and index validation succeeds. A failed refresh keeps the last verified cache or the embedded bundle included in the scanner.
Use cached or embedded definitions without a network request:
php scanner --disable-definitions-update
Choose a persistent private cache root:
php scanner --path-definitions=/var/lib/amwscan/definitions
Maintainers can rebuild the corpus SHA-256 list and advance the bundle sequence with:
php bin/generate-malware-hashes /path/to/verified-corpus 2026.09.06.1
The command preserves the MD5-prefix and legacy-core indexes, writes hashes.json, and recalculates all manifest file metadata. Review and test the complete bundle before publishing it to the repository.
Standalone release
The built in updater keeps the current filename:
php scanner --update
php scanner --version
You can also replace the file from the latest GitHub release:
curl --fail --silent --show-error --location \
--output scanner.new \
https://raw.githubusercontent.com/marcocesarato/PHP-Antimalware-Scanner/master/dist/scanner
php scanner.new --version
mv scanner.new scanner
On Windows PowerShell, replace the last command with Move-Item -Force scanner.new scanner.
Do not bypass certificate checks while downloading an executable scanner. Fix the system trust store or network configuration when verification fails.
Composer installation
Update the package through Composer:
composer update marcocesarato/amwscan
composer show marcocesarato/amwscan
Commit the resulting composer.lock change when the scanner belongs to a project. This keeps development and continuous integration on the same version.
After updating
Run a report scan against a known project and compare the result with the previous version before enabling automated file actions.