Sensitive Info Scanner
This module automatically scans your Drupal configuration for fields that might contain sensitive data, such as API keys or passwords, based on configurable keywords. It then provides an easy-to-use interface to mask these fields using the Credential Mask module, preventing them from being exposed in configuration exports.
Overview
This module scans Drupal configuration storage for fields with names that suggest they may contain sensitive data (API keys, passwords, tokens, credentials) and provides an admin UI to mask them using the Credential Mask module.
Features
Credential Mask keeps secrets out of configuration exports, but you have to know which fields to register with it. This module finds them for you.
- Scans all active configuration and flags any field whose name contains one of a configurable list of keywords (for example
secret,key,password,token). - Lists the flagged fields on a single admin page where you can mask them with just a click. Fields that are already masked appear pre-checked, and unchecking one removes its mask.
- The default keywords are deliberately broad, so some flagged fields won't be sensitive. You choose which ones to mask, and you can tune the keyword list to suit your site.
Once your sensitive fields are masked, you can export your site's configuration and commit it to your repository without exposing their values.
Note: masking affects future exports only. Secrets already committed to your repository remain in its history and should be rotated. Re-run the scan after installing new modules, since they may add new sensitive fields.
Post-Installation
- Grant the Administer Sensitive Info Scanner permission to trusted administrators only. It is a restricted permission, because it allows removing masks.
- Optionally, adjust the keyword list at Administration > Configuration > System > Sensitive Info Scanner > Settings (
/admin/config/system/sensitive-info-scanner/settings). - Go to Administration > Configuration > System > Sensitive Info Scanner (
/admin/config/system/sensitive-info-scanner), select the fields you want to mask, and click Mask Selected Fields. - Export your configuration as usual (for example,
drush config:export).
Additional Requirements
This project requires the Credential Mask module.
Similar projects
Credential Mask handles the actual masking, but you have to enter each field by hand in its settings form. This module adds automatic discovery and a checklist on top of it rather than replacing it.
Depends on
Dependencies of the latest stable release
No dependencies recorded for this project.
Required by
Tracked projects that depend on this one
No tracked projects depend on this one yet.
Activity
Releases
| Version | Type | Core | Notes | Release date | |
|---|---|---|---|---|---|
| 1.0.x-dev | Dev | 10–11 | Initial release | Sep 29, 2026 |