Skip to main content
Drupal is a registered trademark of Dries Buytaert
Release: Drupal 11.3.18 — Update released for Drupal core (11.3.18)! Release: Geocoder 8.x-4.38 — Minor update available for module geocoder (8.x-4.38). Release: UI Icons 2.0.1 — Minor update available for module ui_icons (2.0.1). Release: Vite 1.5.7 — Minor update available for module vite (1.5.7). Release: SearchStax Studio – Site Search 1.13.0 — Minor update available for module searchstax (1.13.0). Release: Prototype: Select 2.0.3 — Minor update available for module prototype_select (2.0.3). Release: Prototype: Select 2.0.2 — Minor update available for module prototype_select (2.0.2). Release: Prototype: Select 2.0.1 — Minor update available for module prototype_select (2.0.1). Usage Milestone: Element Class Formatter — Module element_class_formatter crossed 1,000 active installs. Module Revived: Anti-Duplicates 4.3.0 — Module anti_duplicates updated after 13 months of inactivity (4.3.0).

This module automatically scans your Drupal configuration for fields that might contain sensitive data, such as API keys or passwords, based on configurable keywords. It then provides an easy-to-use interface to mask these fields using the Credential Mask module, preventing them from being exposed in configuration exports.

Overview

This module scans Drupal configuration storage for fields with names that suggest they may contain sensitive data (API keys, passwords, tokens, credentials) and provides an admin UI to mask them using the Credential Mask module.

Features

Credential Mask keeps secrets out of configuration exports, but you have to know which fields to register with it. This module finds them for you.

  • Scans all active configuration and flags any field whose name contains one of a configurable list of keywords (for example secret, key, password, token).
  • Lists the flagged fields on a single admin page where you can mask them with just a click. Fields that are already masked appear pre-checked, and unchecking one removes its mask.
  • The default keywords are deliberately broad, so some flagged fields won't be sensitive. You choose which ones to mask, and you can tune the keyword list to suit your site.

Once your sensitive fields are masked, you can export your site's configuration and commit it to your repository without exposing their values.

Note: masking affects future exports only. Secrets already committed to your repository remain in its history and should be rotated. Re-run the scan after installing new modules, since they may add new sensitive fields.

Post-Installation

  1. Grant the Administer Sensitive Info Scanner permission to trusted administrators only. It is a restricted permission, because it allows removing masks.
  2. Optionally, adjust the keyword list at Administration > Configuration > System > Sensitive Info Scanner > Settings (/admin/config/system/sensitive-info-scanner/settings).
  3. Go to Administration > Configuration > System > Sensitive Info Scanner (/admin/config/system/sensitive-info-scanner), select the fields you want to mask, and click Mask Selected Fields.
  4. Export your configuration as usual (for example, drush config:export).

Additional Requirements

This project requires the Credential Mask module.

Similar projects

Credential Mask handles the actual masking, but you have to enter each field by hand in its settings form. This module adds automatic discovery and a checklist on top of it rather than replacing it.

Depends on

Dependencies of the latest stable release

No dependencies recorded for this project.

Required by

Tracked projects that depend on this one

No tracked projects depend on this one yet.

Activity

Tracked releases
1
Tracked since
Sep 2026
Latest release
7 hours ago
Releases (12 mo)
1 ▲ from 0
Maintenance
Active

Releases

Version Type Core Release date
1.0.x-dev Dev 10–11 Sep 29, 2026