Security Scanner | Pterodactyl v2

Protect your hosting from possible malware and security issues! Scans Pterodactyl server files for security threats.

Security Scanner | Pterodactyl v2.x

Which edition is this? This is the Pterodactyl v2.x edition, built as a native Panel extension. Running Pterodactyl v1.x / 0.7? Use the Security Scanner | Pterodactyl v1 edition instead. Bought the wrong one? Contact us and we'll switch over your license.

New in the v2.x edition: Security Scanner is now a Pterodactyl Panel extension . You install it once on your Panel, not on each Wings node. It automatically scans servers across every node through the Panel's existing daemon connections. No SSH, no PM2, no config.yml , and no API keys to manage.

Requirements

  • Pterodactyl Panel v2.0 or newer (the extension system).
  • A root administrator account on the Panel.
  • The Panel scheduler running (the standard * * * * * php artisan schedule:run cron), needed only for automatic scheduled scans.

Installation

The entire install happens in the Panel. There is nothing to upload to your nodes.

Step 1: Download the extension

Download security-scanner-1.0.0.pteroext from your purchase. This single file contains the whole extension.

Step 2: Install in the Panel

  1. Sign in to your Panel as an administrator.
  2. Go to Admin → Extensions.
  3. Click Install and upload the .pteroext file.
  4. Toggle the extension on to enable it.

That's it. Enabling the extension runs its database migration and publishes its interface automatically. Reload the page after enabling so the Security Scanner entry appears in the admin sidebar.

Multi-node: One install covers all of your nodes, including nodes you add later. The scanner reads each server's files through its node's Wings daemon, so there is no per-node setup and nothing to “link”.

Alternative: install from the command line

Prefer the terminal? From your Panel directory:

php artisan p:extension:install security-scanner-1.0.0.pteroext --enable

Configuration

All configuration lives in the Panel. There is no config.yml. Open Admin → Extensions → Security Scanner → Settings and use the Section dropdown at the top to switch between groups:

Section What you can set
General Enable scheduled scanning, scan frequency (hourly / 6 hours / daily), and the maximum file size to scan.
Checks Turn individual detections on or off: Backdoors, Web Shells, Reverse Shells, Obfuscation, Crypto Miners, Suspicious File Ops, SQL Injection, Network Ops, Container/VM Escape, Known Malware Keywords, and file-hash matching.
Scope Choose all / whitelist / blacklist of servers, and tune the include patterns, excluded path fragments, and plugin whitelist.
Custom rules Add your own regex patterns (with a chosen severity) and lists of known-bad MD5 / SHA256 hashes.
Discord Webhook URL, the minimum severity that triggers a notification, notify-on-clean-scan, and role mentions on critical findings.
Actions Automatically suspend a server when a critical signature is found in it.

Usage

Open Admin → Security Scanner in the sidebar. From the dashboard you can:

  • See findings broken down by severity, category, and affected server at a glance.
  • Click Scan now to scan every in-scope server immediately.
  • Jump straight to any flagged file. Each finding links to the exact file and line in the server's file manager.

When scheduled scanning is enabled, scans also run automatically on your chosen frequency. To trigger a scan from the command line at any time:

php artisan security-scanner:scan

Managing the extension

Action How
Open settings Admin → Extensions → Security Scanner → Settings
Disable without removing Toggle the extension off on the Extensions page (or php artisan p:extension:disable security-scanner)
Update Install the newer .pteroext over the top from the Extensions page
Remove Click Remove on the Extensions page (or php artisan p:extension:remove security-scanner)

Need Help?

Join our Discord Server and open a ticket for support.

© 2026 Security Scanner by BuiltByOtte . All rights reserved.