Skip to the card

Card 753 of 10002026-09-05 issue

Observed arrival · 2026-09-05

Shelltrap puts a webshell scanner directly in the write path

shelltrap.com Observed source
Editorial interest 86/100 Selection signal · not a rating of the site

A server-side security tool for CyberPanel and cPanel that watches file changes, scans uploads in an isolated worker, and blocks PHP files before an application sees them.

Landing page captured for the 2026-09-05 issue.

Field notes

The page describes a write-path workflow rather than a periodic malware scan: fanotify observes filesystem events, a broker hands a read-only descriptor to a restricted worker, and the worker combines ClamAV, YARA 4.5, hash sets, and heuristics. It also documents queue-overflow handling through bounded reconciliation scans. Licensing is per server with unlimited domains, while the cPanel/WHM offering is identified as a beta and the listed price is €14.90 per month including VAT.

Observed signals

Read the marks

Editorial observations of this landing page, not a rating.

OpenPublic substance visible
$PaidCommerce or pricing visible
PrettyNotable craft visible
ProPolished or operationally mature
NicheUnusually specific use

One card from the complete issue

The Receiver Chooses a Memory

351,339 arrived 1,000 judged 1000 catalogued Enter the complete issue
shelltrap.com

Landing page observed 2026-09-05. The live site may have changed.