Skip to main content
Drupal is a registered trademark of Dries Buytaert
Release: Download Tracker 1.0.7 — Minor update available for module download_tracker (1.0.7). Release: Directory2Block Slideshow 1.0.8 — Minor update available for module directory2block_slideshow (1.0.8). Release: Mautic Audiences 1.1.5 — Minor update available for module mautic_audiences (1.1.5). Release: Rightup theme 1.0.3 — Minor update available for theme vartheme_bs5_rightup (1.0.3). Release: CommentOn 1.0.6 — Minor update available for module commenton (1.0.6). Release: ChatGPT Ads 1.0.3 — Minor update available for module chatgpt_ads (1.0.3). Release: RightUp 1.0.2 — Minor update available for module rightup (1.0.2). Release: CronWatch 0.12.1 — Minor update available for module cronwatch (0.12.1). Module Revived: Swagger-PHP OpenAPI 3 documentation generator 1.0.0 — Module swagger_php updated after 10 months of inactivity (1.0.0). Security Coverage: Microsoft Azure AI — Module ai_provider_azure now has official Drupal security advisory coverage.

NIST for Gov

No security coverage
View on drupal.org

Reports that check a Drupal site against NIST SP 800-53 Rev. 5 controls. Built for government and regulated sites. Every report only reads: nothing on the site is changed.

Secrets left visible (IA-5(7), SC-28)

Lists API keys, passwords and tokens stored in plain text, and never shows a value in full (length and last four characters only).

  • High: in exportable configuration and committed to the sync directory, so it's in version control. Remove it and rotate it. IA-5(7).
  • Medium: in exportable configuration, including Key module keys that use the config provider. The next export commits it. IA-5(7).
  • Low: in State. Not exported, but every database backup holds it. SC-28.

Each row says how to fix it: a settings.php override from an environment variable, or the Key module with the environment or file provider. Also available as drush nist:secrets, which exits non-zero while a secret is committed, so CI can stop on it. A Status report entry warns while one is committed.

The controls, from NIST SP 800-53 Rev. 5 (doi.org/10.6028/NIST.SP.800-53r5): IA-5(7) No Embedded Unencrypted Static Authenticators ("Ensure that unencrypted static authenticators are not embedded in applications or other forms of static storage."), and SC-28 Protection of Information at Rest.

Coming from Drupal Cleanup?

This report used to be part of Drupal Cleanup. Installing NIST for Gov takes over its settings. The old address redirects, and drush cleanup:secrets still works.

Requirements

Drupal 10.3 or 11. No other modules.

Related sites

Depends on

Dependencies of the latest stable release

No dependencies recorded for this project.

Required by

Tracked projects that depend on this one

No tracked projects depend on this one yet.

Activity

Tracked releases
1
Tracked since
Oct 2026
Latest release
5 hours ago
Releases (12 mo)
1 ▲ from 0
Maintenance
Active

Releases

Version Type Core Release date
1.0.x-dev Dev 10–11 Oct 3, 2026