Module Description
The Security Review module automates testing for many of the easy-to-make mistakes that render your site insecure.

Get started easily It's quick and easy to get started. Download and enable the module and just hit the "Run checklist" button to see results.

Features Security Review runs the following checks:


* Safe file system permissions (protecting against arbitrary code execution)
* Text formats don't allow dangerous tags (protecting against XSS)
* PHP or Javascript in content (nodes and comments and fields in Drupal 7)
* Safe error reporting (avoiding information disclosure)
* Secure private files
* Only safe upload extensions
* Large amount of database errors (could be sign of SQLi attempts)
* Large amount of failed logins (could be sign of brute-force attempts)
* Responsible Drupal admin permissions (protecting against access misconfiguration)
* Username as password (protecting against brute-force)
* Password included in user emails (avoiding information disclosure)
* PHP execution (protecting against arbitrary code execution)
* Base URL set / D8 Trusted hosts (protecting against some phishing attempts)
* Views access controlled (protecting against information disclosure)

This module does not automatically make changes to your site. You should use the results of the checklist and its resources to manually secure your site. The results of some checks may be incorrect depending on unique factors of your site.

Note that the checks provided by this module do not make for a fully secure site. Security is a process, so you should work to pass all of the Security Review checks and also audit your site for risks this module cannot check for (see below for info on one provider of those services).

Branches
7.x - Still supported but mainly for security coverage 8.x - old D8 + D9 branch, phasing out 2.0.x - Latest branch, D9 + D10

Consult the README.txt for 8.x or 7.x for more information on installation and usage.

More information about security in Drupal You may also be interested in:


* Reading the Drupal Security Report
* For discussion of security consider joining Best Practices in Drupal Security on groups.drupal.org.
* Installing the Paranoia module which will protect your site in a variety of ways.

Project Usage
22501
Creation Date
Changed Date
Security Covered
Covered By Security Advisory
Version Available
Production
Module Summary
The Security Review module aims to automate testing for common security vulnerabilities in Drupal sites.
Data Name
security_review

OPENAI CHATBOT

OPENAI CHATBOT

14:35:06
Generic Chatbot
Hi, I'm a Drupal module expert powered by OpenAI, answering your questions about the Drupal module ecosystem. How can I be helpful today? Please note that we will log your question.