MultiCmsManager

Insecure releases

Alerts for Drupal core and modules on insecure releases

drupal.org marks every release superseded by a security update as "Insecure". It is the same data the Update Status module uses, except we check it for all your sites at once.

The problem

Few people open the available updates report.

Update Status shows insecure releases in each site's admin pages and emails the configured addresses, when someone configured them.

Across dozens of sites with different modules, the forgotten module is exactly the one nobody updates.

How it works

Inventory from the site, releases from drupal.org.

  1. 1

    Inventory

    The agent reads the version and project of core and of every non-core module and theme.

  2. 2

    Release history

    For each project we read the drupal.org release history, with its supported branches.

  3. 3

    Alert

    If the installed version is insecure you get a critical alert with the first security release of its branch.

In detail

In detail.

  • Core, modules and themes downloaded from drupal.org, Drupal 7 included
  • Suggested version in the same branch, to update without jumping releases
  • End-of-life alert for Drupal 7, 8 and 9
  • Custom modules with no drupal.org project are left out
  • You can ignore an alert on one site: it stays listed but stops counting

FAQ

Frequently asked questions

Do you use drupal.org security advisories?

Yes. We read the drupal.org and GitHub advisories through OSV.dev, with title, CVE and link. For Drupal 7 and for modules with no advisory we use the release history, the source of the Update Status module. If several sources publish the same issue you get one alert.

Does it work with Update Status disabled?

Yes. The platform runs the check: the site only needs our module.

Try it on your clients' sites.

During the beta we let in a few agencies at a time and set up the first sites with you.