Drupal is a registered trademark of Dries Buytaert
drupal 11.3.8 Update released for Drupal core (11.3.8)! drupal 11.3.7 Update released for Drupal core (11.3.7)! drupal 11.2.11 Update released for Drupal core (11.2.11)! drupal 10.6.7 Update released for Drupal core (10.6.7)! drupal 10.5.9 Update released for Drupal core (10.5.9)! cms 2.1.1 Update released for Drupal core (2.1.1)! drupal 11.3.6 Update released for Drupal core (11.3.6)! drupal 10.6.6 Update released for Drupal core (10.6.6)! cms 2.1.0 Update released for Drupal core (2.1.0)! video_embed_field 3.1.0 Minor update available for module video_embed_field (3.1.0). bootstrap 8.x-3.40 Minor update available for theme bootstrap (8.x-3.40). menu_link_attributes 8.x-1.7 Minor update available for module menu_link_attributes (8.x-1.7). ckeditor5_premium_features 1.8.1 Minor update available for module ckeditor5_premium_features (1.8.1). ckeditor5_plugin_pack 1.5.2 Minor update available for module ckeditor5_plugin_pack (1.5.2). node_revision_delete 2.1.0 Minor update available for module node_revision_delete (2.1.0). scheduler_content_moderation_integration 3.0.5 Minor update available for module scheduler_content_moderation_integration (3.0.... commerce 3.3.5 Minor update available for module commerce (3.3.5). geocoder 8.x-4.34 Minor update available for module geocoder (8.x-4.34). leaflet 10.4.5 Minor update available for module leaflet (10.4.5). eca 3.1.1 Minor update available for module eca (3.1.1).

A quick setup has been implemented to enhance the security of a generic Drupal project, configurable with variables in a post-installation script. With the aim of streamlining the configuration, installation, and security times of each project.

The OWASP Top 10 was used as a reference framework to ensure it passes 90% of audits. Keep in mind that if any element is overly restrictive, you can relax it at your own risk.

Included Modules

  • Authentication & Access Control: Enforces strong password policies, multi-factor authentication, and session timeouts.
    • Password Policy (Length, character types, history)
    • TFA (Two-Factor Authentication)
    • Autologout
  • Brute Force & Bot Protection: Mitigates automated attacks and unauthorized login attempts.
    • Login Security
    • Flood Control
    • Advban (Advanced Ban)
    • reCAPTCHA
  • Data Exposure Prevention: Hardens HTTP headers and protects user data.
    • Seckit (Security Kit)
    • Username Enumeration Prevention
  • Cryptography & Key Management: Infrastructure for encrypting sensitive data.
    • Key
    • Encrypt
    • Real AES
  • Audit & Logging: Comprehensive tracking for post-incident forensics.
    • Event Log Track (Tracks auth, nodes, config, files, menus, users, etc.)
    • Syslog (Core)

Site-Building Tools

While not strictly security-related, the profile includes essential administration tools to ease site management:

  • Admin Toolbar (along with Tools and Search submodules)
  • Token

Activity

Total releases
3
First release
Apr 2026
Latest release
12 hours ago
Release cadence
0 days
Stability
0% stable

Release Timeline

Releases

Version Type Release date
1.0.2-alpha1 Pre-release Apr 23, 2026
1.0.1-alpha1 Pre-release Apr 23, 2026
1.0.0-alpha1 Pre-release Apr 23, 2026