Compare

imgproxy vs pompelmi

imgproxy processes images, whereas pompelmi scans for malware.

Side by side

What it is
imgproxy:imgproxy is a self-hosted image processing server that resizes, optimizes and transforms images on the fly.
pompelmi:pompelmi is an open-source Node.js wrapper for ClamAV that scans files for malware with a single function call.
Best for
imgproxy:On-premise, high-performance image processing
pompelmi:Zero-dependency ClamAV scanning
Who it’s for
imgproxy:Web developers and DevOps teams needing fast, secure image handling on their own infrastructure.
pompelmi:Node.js developers needing on-premise virus scanning for uploads.
Pricing
imgproxy:Freemium
pompelmi:Open source
Open source
imgproxy:Yes, 11,098 GitHub stars
pompelmi:Yes, 678 GitHub stars
Works with
imgproxy:Docker, Linux packages, Amazon S3, MinIO, Cloudflare R2, Google Cloud Storage, Azure Blob Storage, Prometheus
pompelmi:Node.js, Bun, Deno, Cloudflare Workers, Express, Fastify, NestJS, Next.js
DevHunt upvotes
imgproxy:95
pompelmi:3
Launched on DevHunt
imgproxy:Feb 2024
pompelmi:Sep 2026

imgproxy features

  • On-the-fly resizing & cropping. Resize, crop, fill and rotate images via URL parameters without pre-generating variants.
  • Advanced optimization. Strip metadata, apply PNG quantization, advanced JPEG/WebP compression and SVG minification.
  • Smart AI features. Smart crop, object detection, auto-quality by file size or SSIM, and best-format selection.
  • Watermarking & filters. Add image or text watermarks, shadows, blurs, sharpening, color adjustments and gradients.
  • Security controls. URL signing, request authorization, image-bomb protection and SVG sanitization.
  • Extensive source support. Fetch images from HTTP(S), local files, S3, GCS, Azure Blob, MinIO, Cloudflare R2 and OpenStack Swift.

pompelmi features

  • One-function API. Call pompelmi.scan(path) and await a typed verdict without config objects.
  • Typed verdicts. Returns Verdict.Clean, Verdict.Malicious, or Verdict.ScanError as Symbol constants.
  • Cross-platform. Runs on macOS, Linux, and Windows wherever ClamAV is installed.
  • No daemon required. Uses clamscan directly, avoiding background clamd processes.
  • Zero runtime dependencies. Relies only on Node's built-in child_process, no extra packages.
  • Exit-code mapping. Maps ClamAV exit codes directly, eliminating stdout parsing.

Based on each tool's website and DevHunt data. Details may change; check the official sites.