Security Scanner for Drupal installations to quickly identify potential security issues, server reputation and other aspects of the web server.
Drupal is one of the worlds leading content management system. It is used on a large number of high profile sites. It is known for its security and being extensible. Perform a simple Drupal security test by filling out the following form. Our system will test your website in a non-intrusive manner and display any discovered vulnerabilities or configuration errors.
Launch Drupal (Droopescan) Security Scan
Perform an immediate Free Drupal Scan with a low impact test.
Check any Drupal based site and get a high level overview of the sites security posture. Once you see how easy it is grab a membership and test Drupal with Droopescan, Nikto, OpenVAS and more.
Items checked in the FREE scan
Attempt to detect version of Drupal Core
Find plugins in HTML response
Identify theme in use
List client side JS and iframes in page
Test for directory indexing enabled on key locations
Threat Intel & Blacklisting Checks
Membership is required for advanced Drupal Enumeration & Vulnerability Scanners
This scan will test a Drupal installation for common security issues, mis-configurations as well as performing a web reputation analysis of sites that are being linked and sites that are hosted on the same IP address. The Free scan is a passive scan in that all the information gathered is from performing regular web requests against the specified site.
The more aggressive second option uses the excellent droopescan to brute force theme and module/plugin paths in an attempt to discover the sites attack surface. With information about the installed extras known vulnerabilities can be exploited or further security testing can be more targeted.
Our range of online web security testing for Drupal and other web platforms has you covered for a variety of use cases.
The freely available tools perform analysis from a simple page grab. Through examination of the HTML source code, javascript and a few other open publicly accessible pages it is possible to gain immediate insights into the state of security on the target site. This is without sending any aggressive security scanning, using only passive analysis methods.
Our second form of scanning involves using active security testing tools (OpenVAS, Nikto, Droopescan are examples) that send hundreds of requests against the target site to enumerate and find security issues (vulnerabilities) that are not immediately apparent from passive analysis.
Droopescan is an open source project developed in python. One of the things we love about open source security solutions is that you can not only run the tool and get results; but also dig into the code and understand what is being tested and why it is being tested. Knowledge is the ultimate cyber weapon.
To run the tool locally for yourself grab the latest version from github. Another option is to use the popular Kali Linux distribution that includes droopescan.