Protect Ghost uploads before they reach production.
CypherScan securely scans every uploaded file using a presigned upload workflow and can automatically block suspicious or malicious files before they become available inside Ghost CMS.
- Secure presigned upload workflow
- Malware detection
- Secret detection
- Automatic malicious file blocking
- Configurable fail-open / fail-closed behavior
- Local storage compatibility
- Configurable request timeout
- Debug logging
- Lightweight Ghost storage adapter
- Ghost CMS 6.x
- Node.js 20+
- CypherScan API key
Clone or install the storage adapter inside your Ghost installation:
content/adapters/storage/cypherscan
Configure Ghost to use the adapter for images, media and files.
Restart Ghost.
Example:
{
"storage": {
"active": "cypherscan",
"images": {
"adapter": "cypherscan"
},
"media": {
"adapter": "cypherscan"
},
"files": {
"adapter": "cypherscan"
},
"cypherscan": {
"apiKey": "YOUR_API_KEY",
"apiBaseUrl": "https://cyphernetsecurity.com",
"timeout": 30000,
"failOpen": true,
"debug": false
}
}
}When a file is uploaded:
- The storage adapter requests a presigned upload URL from the CypherScan API.
- The file is uploaded securely to temporary object storage.
- CypherScan scans the uploaded object.
- A scan verdict is returned.
- Clean files remain available.
- Suspicious or malicious files are automatically blocked.
Ghost Upload
│
▼
CypherScan Storage Adapter
│
▼
Request Presigned Upload URL
│
▼
Temporary Secure Upload
│
▼
CypherScan Scan
│
▼
Verdict
│
├── Clean ─────► Upload allowed
│
└── Blocked ───► Upload rejected
Upload detected
│
▼
Presigned Upload
│
▼
CypherScan Scan
│
▼
Verdict: Clean
│
▼
File available inside Ghost
CypherScan supports two operating modes.
Uploads continue if the scanning service is temporarily unavailable.
Recommended for development environments.
Uploads are rejected when the scan cannot be completed.
Recommended for production environments requiring strict upload enforcement.
When debug is enabled, the adapter logs:
- File name
- MIME type
- File size
- Scan status
- Scan verdict
- Scan ID
- Upload decision
Validated with:
- Clean image uploads
- Malware detection (EICAR)
- API unavailable (
failOpen=true) - API unavailable (
failOpen=false) - Local storage
- Ghost CMS 6.x
Ghost adapter scans use the canonical CypherScan API workflow:
POST /api/v1/upload/presign- Upload the file to the returned temporary URL
POST /api/v1/scanwith the returnedobjectKey
The adapter sends a stable client identity to CypherScan:
x-cypherscan-client: ghost-plugin
The presigned storage PUT remains storage-only and does not receive CypherScan authentication or client headers.
With an active CypherScan Agent subscription, successful authenticated scans automatically become API_INTEGRATION Agent observations. No second Agent event call is required.
Agent can then use those observations for meaningful-change detection, bounded verification, Controller attention decisions, alerts, and activity history.
- Scan history
- Detailed scan reports
- Quarantine support
- Policy-based upload rules
MIT License
Copyright (c) 2026 CypherNet Security Inc.
See the LICENSE file for details.
- Website: https://cyphernetsecurity.com
- GitHub: https://github.com/cyphernetsecurity
Built by CypherNet Security Inc.