Drupal Vulnerability Scanner
Fast, accurate and free online drupal vulnerability scanner tool running directly in your browser.
-
1Enter data
Enter content, paste text or load a file from disk. -
2Click the button
The tool will immediately process your data in the browser. -
3Get the result
Copy the finished text or save the file to your device.
return "Result ready in 0.1s";
}
Drupal Vulnerability Scanner
Run a quick, non-invasive scan of a Drupal installation for common issues: outdated core versions (with many known CVEs), exposed configuration files, accessible CHANGELOG/README files, and directory listing errors. This tool is intended only for testing systems you are authorized to test.
No significant issues were detected based on the tests performed. This is a quick, superficial scan and does not replace a full security audit.
Rate this tool:
Related tools
Other tools you may find usefulDrupal Vulnerability Scanner in Webp - a quick overview of Drupal website security
Drupal Vulnerability Scanner in Webp is a convenient online tool that in a few moments checks your Drupal website for known configuration problems, core version, publicly available files such as CHANGELOG.txt, settings.php or install.php and characteristic error messages so that you can quickly assess whether your website requires cleaning up basic security settings without installing heavy software and without having to delve into technical details.
The tool runs entirely in the browser on Webp servers, and you just enter the URL of your Drupal-based site, set a timeout, and decide whether the scanner should track redirects and check specific files, and then with one click you run a light security reconnaissance that does not try to break security, but analyzes what the website provides externally in the HTTP response and in publicly available resources.
What exactly does the Drupal Vulnerability Scanner in Webp check
The Drupal Scanner in Webp combines several simple but very practical modules that together give a quick picture of the status of your installation, starting from detecting whether the website actually runs on Drupal, through trying to guess the version based on HTTP headers and CHANGELOG files, to checking popular paths such as settings.php, install.php, system.module or directories that may reveal file listings, as well as detecting characteristic error messages and debug mode messages that should not be visible to ordinary users.
The most important functions of the Drupal scanner
- Detecting whether the website runs on Drupal based on HTTP headers and meta generator in the website code.
- Trying to read or estimate the Drupal core version from the CHANGELOG.txt or core/CHANGELOG.txt headers and files.
- Analyze the basic risks associated with the version, for example whether it is a very old Drupal 7 or earlier.
- Checking popular Drupal paths and files, including settings.php, install.php, system.module and listing directories.
- Detect error and debug messages that may reveal details of the server environment or application code.
- A summary of the HTTP response, headers, and a snippet of content so you can see what the page reveals to the outside world.
Who is Drupal Vulnerability Scanner for?
- For Drupal website owners who want to quickly check basic security elements without deep technical knowledge.
- For administrators and devs who are looking for a lightweight tool for the first recovery after implementing a new version of the website.
- For agencies and software houses that maintain multiple Drupal websites and need quick control of basic risks.
- For people learning Drupal security who want to see what a simple analysis of what a site reveals on the web looks like.<