cypherscan-ghost
v0.1.0
Published
Scan uploaded files with CypherScan before they enter Ghost CMS workflows.
Maintainers
Readme
CypherScan for Ghost
Protect Ghost uploads before they reach production.
CypherScan securely scans every uploaded file using a presigned upload workflow and can automatically block suspicious or malicious files before they become available inside Ghost CMS.
Features
- Secure presigned upload workflow
- Malware detection
- Secret detection
- Automatic malicious file blocking
- Configurable fail-open / fail-closed behavior
- Local storage compatibility
- Configurable request timeout
- Debug logging
- Lightweight Ghost storage adapter
Requirements
- Ghost CMS 6.x
- Node.js 20+
- CypherScan API key
Installation
Clone or install the storage adapter inside your Ghost installation:
content/adapters/storage/cypherscanConfigure Ghost to use the adapter for images, media and files.
Restart Ghost.
Configuration
Example:
{
"storage": {
"active": "cypherscan",
"images": {
"adapter": "cypherscan"
},
"media": {
"adapter": "cypherscan"
},
"files": {
"adapter": "cypherscan"
},
"cypherscan": {
"apiKey": "YOUR_API_KEY",
"apiBaseUrl": "https://cyphernetsecurity.com",
"timeout": 30000,
"failOpen": true,
"debug": false
}
}
}How it works
When a file is uploaded:
- The storage adapter requests a presigned upload URL from the CypherScan API.
- The file is uploaded securely to temporary object storage.
- CypherScan scans the uploaded object.
- A scan verdict is returned.
- Clean files remain available.
- Suspicious or malicious files are automatically blocked.
Architecture
Ghost Upload
│
▼
CypherScan Storage Adapter
│
▼
Request Presigned Upload URL
│
▼
Temporary Secure Upload
│
▼
CypherScan Scan
│
▼
Verdict
│
├── Clean ─────► Upload allowed
│
└── Blocked ───► Upload rejectedExample
Upload detected
│
▼
Presigned Upload
│
▼
CypherScan Scan
│
▼
Verdict: Clean
│
▼
File available inside GhostFail Open / Fail Closed
CypherScan supports two operating modes.
Fail Open
Uploads continue if the scanning service is temporarily unavailable.
Recommended for development environments.
Fail Closed
Uploads are rejected when the scan cannot be completed.
Recommended for production environments requiring strict upload enforcement.
Debug logging
When debug is enabled, the adapter logs:
- File name
- MIME type
- File size
- Scan status
- Scan verdict
- Scan ID
- Upload decision
Tested
Validated with:
- Clean image uploads
- Malware detection (EICAR)
- API unavailable (
failOpen=true) - API unavailable (
failOpen=false) - Local storage
- Ghost CMS 6.x
Roadmap
- Scan history
- Detailed scan reports
- Quarantine support
- Policy-based upload rules
License
MIT License
Copyright (c) 2026 CypherNet Security Inc.
See the LICENSE file for details.
Links
- Website: https://cyphernetsecurity.com
- GitHub: https://github.com/cyphernetsecurity
Built by CypherNet Security Inc.
