Skip to main content
Drupal is a registered trademark of Dries Buytaert
Release: OpenID Connect / OAuth client 3.0.0-alpha9 New alpha version released for module openid_connect (3.0.0-alpha9). Release: Opensolr Search 4.5.0 Minor update available for module opensolr_search (4.5.0). Release: Timelinr 1.0.1 Minor update available for module timelinr (1.0.1). Usage Milestone: Simplify Module simplify crossed 10,000 active installs. Usage Milestone: Views Reference Filter Module entityreference_filter crossed 10,000 active installs. Usage Milestone: Dropdown Language Module dropdown_language crossed 10,000 active installs. Usage Milestone: Paragraphs Browser Module paragraphs_browser crossed 10,000 active installs. Usage Milestone: OpenAPI Module openapi crossed 10,000 active installs. Usage Milestone: Decoupled Router Module decoupled_router crossed 10,000 active installs. Module Revived: Entityqueue Buttons 1.1.2 Module entityqueue_buttons updated after 8 months of inactivity (1.1.2).

Security Review

16,938 sites Security covered Drupal 10–11
View on drupal.org

The Security Review module automates testing for common security mistakes on your website. It checks for issues like insecure file permissions, dangerous text formats, and unsafe uploads, providing a checklist to help you manually secure your site.

The Security Review module automates testing for many of the easy-to-make mistakes that render your site insecure.

Get started easily

It's quick and easy to get started. Download and enable the module and just hit the "Run checklist" button to see results. This module is meant to run in your production environment. You might choose to run it in other environments (if you have them), but some checks need to run in production to be effective.

Features

Security Review runs the following checks:

  • Safe file system permissions (protecting against arbitrary code execution)
  • Text formats don't allow dangerous tags (protecting against XSS)
  • PHP or Javascript in content (nodes and comments and fields in Drupal 7)
  • Safe error reporting (avoiding information disclosure)
  • Secure private files
  • Only safe upload extensions
  • Large amount of database errors (could be sign of SQLi attempts)
  • Large amount of failed logins (could be sign of brute-force attempts)
  • Responsible Drupal admin permissions (protecting against access misconfiguration)
  • Username as password (protecting against brute-force)
  • Password included in user emails (avoiding information disclosure)
  • PHP execution (protecting against arbitrary code execution)
  • Base URL set / D8 Trusted hosts (protecting against some phishing attempts)
  • Views access controlled (protecting against information disclosure)

This module does not automatically make changes to your site. You should use the results of the checklist and its resources to manually secure your site. The results of some checks may be incorrect depending on unique factors of your site.

Note that the checks provided by this module do not make for a fully secure site. Security is a process, so you should work to pass all of the Security Review checks and also audit your site for risks this module cannot check for (see below for info on one provider of those services).

Consult the README.txt for 8.x or 7.x for more information on installation and usage.

More information about security in Drupal

You may also be interested in:

Depends on

Dependencies of the latest stable release

No dependencies recorded for this project.

Required by

Tracked projects that depend on this one

No tracked projects depend on this one yet.

Activity

Tracked releases
7
Tracked since
Oct 2024
Latest release
1 month ago
Releases (12 mo)
3 ▼ from 4
Maintenance
Active

Release Timeline

Releases

Version Type Core Release date
4.0.x-dev Dev 11 Jul 9, 2026
3.1.3 Stable 10–11 Jan 23, 2026
3.1.2 Stable 10–11 Jan 2, 2026
3.1.1 Stable 10–11 Nov 18, 2024
3.1.0 Stable 10–11 Nov 15, 2024
3.0.4 Stable 10–11 Nov 15, 2024
3.1.x-dev Dev 10–11 Oct 21, 2024