OSS Tanbou

scan files, archives, and mail with signature databases to detect viruses, trojans, malware, and other malicious content

About these scores

OSS scale score is an unbounded metric that log-compresses and weights Stars, Watchers, Forks, and Contributors. Discovery score is the current OSS scale score minus the score at discovery. Update pace is commits in the last 30 days, growth momentum is the OSS scale score difference within the recent observation window, and OSS health is a 0–100 rating based on available recency, Community Health, and release data.

Stars
7,314
Primary language
C
License
GPL-2.0
Repository last updated
Aug 27, 2026
On this page

Overview

ClamAV is an open-source antivirus engine for detecting viruses, trojans, malware, and other malicious content. It provides clamscan for direct scans, the clamd daemon for persistent scanning, FreshClam for signature-database updates, libclamav for application integration, and official Docker images.

Features and best fit

Based on official documentation; not hands-on tested · Content checked:

Key features

Scan files and archives with signature databases

clamscan scans files and directories directly, while clamd and clamdscan support a persistent scanning service. The engine includes parsers for archives and many file formats.

Sources: [1][2]

Keep malware signatures current with FreshClam

Detection uses signature databases. Official Docker images provide versioned images with bundled databases and _base images intended for externally persisted database volumes updated by FreshClam.

Sources: [2]

Choose CLI, daemon, or library integration

ClamAV can run as command-line tools, a long-running daemon, or libclamav embedded in an application. Source builds can also be configured for libclamav-only use.

Sources: [3]

Best fit

Fits upload scanning, mail gateways, and file-server malware checks

It is useful when servers that accept or store files need a separate scanner service or embeddable library for malware checks.

Sources: [1][2]

Before adoption

Update both the engine and the signature database

Older engines can retain parser vulnerabilities, and 1.5.4 itself is a security-fix patch release. Maintain engine releases and signature updates as separate operational lifecycles.

Sources: [4][5]

Source builds require CMake, C and Rust toolchains, and multiple libraries

The 1.5.4 build reference requires CMake 3.17+, a C compiler, and Rust, alongside dependencies including libxml2, PCRE2, OpenSSL, and json-c. Compare source builds with distribution packages or official images.

Sources: [3]

Check third-party component licenses separately

The main project is GPLv2, but bundled components include differently licensed code such as Yara, zlib, libmspack, and UnRAR. UnRAR is kept separate at runtime because its license is not GPLv2-compatible.

Sources: [1][6]

Official sources

  1. [1]ClamAV 1.5.4 README(2026-10-03)
  2. [2]ClamAV 1.5.4 Docker guide(2026-10-03)
  3. [3]ClamAV 1.5.4 build reference(2026-10-03)
  4. [4]ClamAV 1.5.4 release notes(2026-10-03)
  5. [5]ClamAV 1.5.4 release(2026-10-03)
  6. [6]ClamAV licensing notes(2026-10-03)
Supplemental curator note

ClamAV fits server-side upload scanning, mail gateways, and other workflows that need malware checks outside an endpoint product. Detection quality depends on signature freshness, so monitor engine upgrades and FreshClam database updates as separate operational concerns.

Try it in 3 steps

  1. 1

    Pull the official ClamAV 1.5.4 Docker image

    Use the pinned image that includes signature databases. For repeated operation, consider a database volume and the _base image.

    docker pull clamav/clamav:1.5.4
  2. 2

    Verify the scanner version

    Check the ClamAV version inside the container without installing it directly on the host.

    docker run --rm clamav/clamav:1.5.4 clamscan --version
  3. 3

    Scan a read-only mounted sample file

    Mount a local sample directory read-only and scan it. For real workloads, also verify signature-database freshness.

    mkdir -p clamav-scan && printf 'hello\n' > clamav-scan/sample.txt && docker run --rm --mount type=bind,source="$PWD/clamav-scan",target=/scandir,readonly clamav/clamav:1.5.4 clamscan /scandir
Check the official README

Growth

Growth trends · Last 30 days

7,314 Stars

Trend data is still being collected.

Development activity

Last 90 days · weekly

Commits (last 30 days)
0
Open PRs
66

Development activity is still being collected.

Built with

Categories and tags

GitHub data

GitHub dataView detailed GitHub data

GitHub Topics

  • clamav
  • gplv2
  • antivirus
  • open-source
Stars
7,314
Forks
928
Watchers
141
Open issues
336
Contributors
137
Owner type
Organization
Primary language
C
License
GPL-2.0
Repository last updated
Aug 27, 2026
Write a related article

Share a guide or use case for this OSS in Markdown. Articles are published after administrator approval.

Report incorrect information

Tell us if any listing information is incorrect or outdated.

After reading this page, do you know what to do next?