Drupal is a registered trademark of Dries Buytaert
cms 2.1.3 Update released for Drupal core (2.1.3)! drupal 10.5.11 Update released for Drupal core (10.5.11)! drupal 11.3.11 Update released for Drupal core (11.3.11)! drupal 11.2.13 Update released for Drupal core (11.2.13)! drupal 10.6.10 Update released for Drupal core (10.6.10)! cms 2.1.2 Update released for Drupal core (2.1.2)! drupal 11.1.10 Update released for Drupal core (11.1.10)! drupal 10.5.10 Update released for Drupal core (10.5.10)! drupal 10.4.10 Update released for Drupal core (10.4.10)! drupal 11.2.12 Update released for Drupal core (11.2.12)! drupal 11.3.10 Update released for Drupal core (11.3.10)! drupal 10.6.9 Update released for Drupal core (10.6.9)! drupal 10.6.8 Update released for Drupal core (10.6.8)! drupal 11.3.9 Update released for Drupal core (11.3.9)! drupal 11.3.8 Update released for Drupal core (11.3.8)! drupal 11.3.7 Update released for Drupal core (11.3.7)! drupal 11.2.11 Update released for Drupal core (11.2.11)! drupal 10.6.7 Update released for Drupal core (10.6.7)! drupal 10.5.9 Update released for Drupal core (10.5.9)! cms 2.1.1 Update released for Drupal core (2.1.1)!

A quick setup has been implemented to enhance the security of a generic Drupal project, configurable with variables in a post-installation script. With the aim of streamlining the configuration, installation, and security times of each project.

The OWASP Top 10 was used as a reference framework to ensure it passes 90% of audits. Keep in mind that if any element is overly restrictive, you can relax it at your own risk.

Included Modules

  • Authentication & Access Control: Enforces strong password policies, multi-factor authentication, and session timeouts.
    • Password Policy (Length, character types, history)
    • TFA (Two-Factor Authentication)
    • Autologout
  • Brute Force & Bot Protection: Mitigates automated attacks and unauthorized login attempts.
    • Login Security
    • Flood Control
    • Advban (Advanced Ban)
    • reCAPTCHA
  • Data Exposure Prevention: Hardens HTTP headers and protects user data.
    • Seckit (Security Kit)
    • Username Enumeration Prevention
  • Cryptography & Key Management: Infrastructure for encrypting sensitive data.
    • Key
    • Encrypt
    • Real AES
  • Audit & Logging: Comprehensive tracking for post-incident forensics.
    • Event Log Track (Tracks auth, nodes, config, files, menus, users, etc.)
    • Syslog (Core)

Site-Building Tools

While not strictly security-related, the profile includes essential administration tools to ease site management:

  • Admin Toolbar (along with Tools and Search submodules)
  • Token

Activity

Total releases
4
First release
Apr 2026
Latest release
1 month ago
Release cadence
2 days
Stability
0% stable

Release Timeline

Releases

Version Type Release date
1.0.2-rc1 Pre-release Apr 28, 2026
1.0.2-alpha1 Pre-release Apr 23, 2026
1.0.1-alpha1 Pre-release Apr 23, 2026
1.0.0-alpha1 Pre-release Apr 23, 2026