strapi-plugin-cypherscan
v0.1.15
Published
CypherScan plugin for Strapi uploads
Maintainers
Readme
CypherScan for Strapi
Protect Strapi uploads before they reach production.
CypherScan securely scans every uploaded file using a presigned upload workflow and can automatically block suspicious or malicious files before they become available inside Strapi.
Features
- Secure presigned upload workflow
- Malware detection
- Secret detection
- Automatic malicious file blocking
- Configurable fail-open / fail-closed behavior
- Native Strapi integration
- Configurable request timeout
- Debug logging
- Lightweight plugin architecture
Requirements
- Strapi 5+
- Node.js 20+
- CypherScan API key
Installation
Install the plugin:
npm install strapi-plugin-cypherscanRestart your Strapi application after installation.
Configuration
Configure your environment variables:
CYPHERSCAN_API_KEY=cs_xxxxxxxxxxxxxxxxx
CYPHERSCAN_BASE_URL=https://cyphernetsecurity.comRestart Strapi after updating your environment.
How it works
When a file is uploaded:
- The plugin requests a presigned upload URL from the CypherScan API.
- The file is uploaded securely to temporary object storage.
- CypherScan scans the uploaded object.
- A scan verdict is returned.
- Clean files remain available.
- Suspicious or malicious files are automatically removed.
Architecture
User Upload
│
▼
Strapi Upload Hook
│
▼
Request Presigned Upload URL
│
▼
Temporary Secure Upload
│
▼
CypherScan Scan
│
▼
Verdict
│
├── Clean ─────► Upload allowed
│
└── Blocked ───► Upload removedExample
Upload detected
│
▼
Presigned Upload
│
▼
CypherScan Scan
│
▼
Verdict: Clean
│
▼
File available inside StrapiFail Open / Fail Closed
CypherScan supports two operating modes.
Fail Open
Uploads continue if the scanning service is temporarily unavailable.
Recommended for development environments.
Fail Closed
Uploads are rejected when the scan cannot be completed.
Recommended for production environments requiring strict upload enforcement.
Debug Logging
When debug mode is enabled, the plugin logs:
- File name
- MIME type
- File size
- Presign request status
- Upload status
- Scan status
- Scan verdict
- Risk level
- Scan ID
- Upload decision
Tested
Validated with:
- Clean uploads
- Malware detection (EICAR)
- API unavailable (
failOpen=true) - API unavailable (
failOpen=false) - Automatic blocked file removal
- Strapi 5.x
CypherScan Agent
Strapi plugin scans use the canonical CypherScan API workflow:
POST /api/v1/upload/presign- Upload the file to the returned temporary URL
POST /api/v1/scanwith the returnedobjectKey
The plugin sends a stable client identity:
x-cypherscan-client: strapi-pluginWith an active CypherScan Agent subscription, successful authenticated scans
automatically become API_INTEGRATION Agent observations. No second Agent
event call is required.
Agent can then use those observations for meaningful-change detection, bounded verification, Controller attention decisions, alerts, and activity history.
Roadmap
- Scan history
- Detailed scan reports
- Quarantine support
- Policy-based upload rules
License
MIT License
Copyright (c) 2026 CypherNet Security Inc.
See the LICENSE file for details.
Links
- Website: https://cyphernetsecurity.com
- Marketplace: https://market.strapi.io/plugins/strapi-plugin-cypherscan
- GitHub: https://github.com/cyphernetsecurity/cypherscan-strapi
Built by CypherNet Security Inc.
