MultiCmsManager

Drupal for agencies

Drupal site monitoring for web agencies

Drupal 7, 8, 9, 10 and 11 are all still in production, often in the same client portfolio. Our module follows them with the same features as the other CMSs and reads security data from drupal.org.

The problem

Mass attacks on Drupal have already happened.

Drupalgeddon in 2014 and Drupalgeddon2 in 2018 hit thousands of sites within days: new administrators, backdoors in the database, JavaScript miners in core files, PHP shells in the public files folder.

The Update Status module only warns about insecure releases to whoever opens the admin pages. With dozens of sites, nobody opens them every day.

How it works

Drupal gives the data, drupal.org the releases.

  1. 1

    Native module

    Extract it into modules/custom (Drupal 7: sites/all/modules), enable it under Extend and connect it with a one-time code.

  2. 2

    Inventory

    Modules and themes with project and version, administrators, database and settings come from Drupal itself.

  3. 3

    Checks

    Core integrity against the official archive, insecure releases, suspicious files, security events and backups.

In detail

What it checks on a Drupal site.

  • Drupal 7 and 8.9 to 11, Composer projects and archives
  • Core and modules on releases drupal.org marks as insecure
  • Core integrity, also when Composer installs files in a different form from the archive
  • New administrators, promotions, logins and installed modules
  • Drupalgeddon backdoors in the menu_router table on Drupal 7
  • One-click login, encrypted backups and restore

FAQ

Frequently asked questions

How do I install the module?

Download the zip from the dashboard, extract it among the site's modules, enable it under Extend and paste the connection code in Configuration, System, MCM Agent.

Do core updates done with Composer raise false alarms?

No. We compare changed files with the official archive of the new version and with the module releases on drupal.org, and you get a single update notification.

Does it work with PostgreSQL?

Monitoring and security do. Backups and restores need MySQL or MariaDB.

Try it on your clients' sites.

During the beta we let in a few agencies at a time and set up the first sites with you.