How to audit a Drupal site in 2026
Which modules are outdated?
Deeper than a manual audit or a tool. At the scale AI agents attack.
The audit starts after signup. $49 for one month. Your report stays in your account.
- Core and modules
- Known CVEs
- Installer leftovers
- Users and files
01 / 08·running
Public surface
Other hosts and open ports
Signals
- Core and modulesThe Drupal release and modules your site is actually serving, not a guess.
- Known CVEsPublished holes in that core and in the modules we could see.
- Installer leftoversupdate.php, authorize.php, and install.php still answering after go-live.
- Users and filesOpen registration, user enumeration, and a files directory that lists itself.
How the Drupal audit runs
What else is on this domain
Other hostnames on the same domain, then the ports those servers leave open, before anything Drupal-specific.
Subdomains
Staging, old admin hosts, and the other names on your domain.
Live hosts
Which of those names actually answer.
Open ports
What is listening, including the version when the server says it.
On your Drupal
Your Drupal core and modules, then the installer files, user accounts, and public files directory someone can still request.
Core and modules
The Drupal release and modules your site is actually serving, not a guess.
Known CVEs
Published holes in that core and in the modules we could see.
Installer leftovers
update.php, authorize.php, and install.php still answering after go-live.
Users and files
Open registration, user enumeration, and a files directory that lists itself.
A report you can act on
Each issue names the host, shows the evidence, and says what to fix. Anything we could not confirm stays marked that way.
Evidence
The URL or file that proved it.
CVE ids
Only when we saw the version the advisory is about.
Account
The report opens after the $49 month is paid.
Questions about a Drupal audit
What the run covers, and when the report opens in the account.
Contact usAudit Drupal from the outside.
Deeper than a manual audit or a tool. At the scale AI agents attack.