Skip to main content
Drupal is a registered trademark of Dries Buytaert
Release: OpenID Connect / OAuth client 3.0.0-alpha9 New alpha version released for module openid_connect (3.0.0-alpha9). Release: Opensolr Search 4.5.0 Minor update available for module opensolr_search (4.5.0). Release: Timelinr 1.0.1 Minor update available for module timelinr (1.0.1). Usage Milestone: Simplify Module simplify crossed 10,000 active installs. Usage Milestone: Views Reference Filter Module entityreference_filter crossed 10,000 active installs. Usage Milestone: Dropdown Language Module dropdown_language crossed 10,000 active installs. Usage Milestone: Paragraphs Browser Module paragraphs_browser crossed 10,000 active installs. Usage Milestone: OpenAPI Module openapi crossed 10,000 active installs. Usage Milestone: Decoupled Router Module decoupled_router crossed 10,000 active installs. Module Revived: Entityqueue Buttons 1.1.2 Module entityqueue_buttons updated after 8 months of inactivity (1.1.2).

This module scans content for security risks, such as leaked personally identifiable information (PII) or credentials, and assigns a risk score to help prevent accidental data exposure. It can also scan existing content and integrate with AI coding assistants for automated security audits.

This module is part of the AI module ecosystem and included in DXPR CMS.

Sensitive Data Leaks in Content Are Invisible Until They're Not

A support article accidentally includes a customer's email. A developer pastes an API key into a documentation page. A case study reveals a client's internal project name. These things happen, and by the time someone notices, the damage is done. This module scans every piece of content for security risks before they become incidents.

You need AI Content Security Audit if

  • Your content includes real customer data, internal systems, or technical details that could leak
  • Compliance regulations (GDPR, HIPAA, SOC 2) require you to prevent PII disclosure in published content
  • Developers or technical writers contribute content that may contain credentials, API keys, or tokens
  • You want automated screening of content before publication, not manual review that misses things

What You Get

  • Risk score per page (0-100)

    Every content entity gets a security risk score per detection vector: 0 means no risk, 100 means critical. Displayed as a visual gauge so editors immediately see which pages need attention.

  • Built-in detection for common leaks

    Ships with two security vectors ready to go:

    • PII Disclosure: names, addresses, phone numbers, SSNs, email addresses
    • Credentials Disclosure: API keys, passwords, tokens, database credentials
  • Custom security vectors

    Add your own detection vectors for organisation-specific risks: proprietary project names, internal URLs, partner data, anything your security policy requires.

  • Batch scanning for existing content

    Audit your entire content library to find pages that were published before security review was in place. Prioritise remediation by risk score.

  • AI Coding Assistant Integration

    Security audit analysis is available to AI coding assistants through the Analyze module's built-in Agent Skills file. Run drush analyze:setup-ai to enable, then ask naturally:

    • "Scan all content for security risks"
    • "Check if any pages expose PII or credentials"
    • "Run a security audit on all published articles"

    Compatible with Claude Code, Codex CLI, Gemini CLI, GitHub Copilot, Cursor, and other tools supporting the standard.

Getting Started

  1. Set up an AI provider at /admin/config/ai/providers
  2. Review security vectors at /admin/config/analyze/content-security-audit (or add custom ones)
  3. Enable the analyzer per content type at /admin/config/content/analyze-settings
  4. Open any content entity's Analyze tab to see risk scores

Prefer a turnkey demo site?

Spin up DXPR CMS: Drupal pre-configured with DXPR Builder, DXPR Theme, the full Analyze suite including AI Security Audit, and security best practices out of the box.

Get DXPR CMS »

Additional requirements

This module requires:

Related Modules

  • Analyze - Required. Provides the plugin framework, Analyze tab, and batch processing this module extends
  • AI - Required. Supplies the LLM provider used for evaluating content against security vectors
  • Views Color Scales - Required. Renders colour-coded risk score columns in the security audit Views report
  • AI Content Marketing Audit - Sibling Analyze plugin that scores marketing effectiveness
  • AI Sentiments Analysis - Sibling Analyze plugin that measures tone, trust, and reading level
  • Analyze Broken Links - Sibling Analyze plugin that checks link health without AI

AI Content Security Audit is part of the Analyze suite included in DXPR CMS, a turnkey marketing CMS for Drupal that combines content analysis, a premium Drupal theme, and a drag-and-drop layout builder. See getting started or explore pricing.

Depends on

Dependencies of the latest stable release

Required by

Tracked projects that depend on this one

No tracked projects depend on this one yet.

Activity

Tracked releases
12
Tracked since
Aug 2025
Latest release
3 weeks ago
Releases (12 mo)
7 ▲ from 5
Maintenance
Active

Release Timeline

Releases

Version Type Core Release date
1.3.0 Stable 10–11 Aug 7, 2026
1.2.0 Stable 10–11 Apr 7, 2026
1.1.1 Stable 10–11 Jan 29, 2026
1.1.0 Stable 10–11 Jan 5, 2026
1.0.2 Stable 10–11 Sep 25, 2025
1.0.1 Stable 10–11 Sep 25, 2025
1.0.0 Stable 10–11 Sep 11, 2025
1.0.0-beta4 Pre-release 10–11 Aug 22, 2025
1.0.0-beta3 Pre-release 10–11 Aug 5, 2025
1.0.0-beta2 Pre-release 10–11 Aug 5, 2025
1.0.0-beta1 Pre-release 10–11 Aug 5, 2025
1.x-dev Dev 10–11 Aug 5, 2025