Drupal security & health monitoring
Drubix watches every site your agency manages, checks it against Drupal.org's security advisories, and tells you exactly what to run to fix it — before it becomes an incident call.
No credit card. Paste a URL, get a report in under a minute.
$ drubix scan client-portal.example.com
Drupal 10.1.2 detected · 34 modules found
Checking against 1,842 known advisories…
HIGHWebform — Cross-site scripting — SA-CONTRIB-2026-014
Installed: webform 6.2.1 · Fixed in: 6.2.3
✓ 33 other modules clear
The problem
Every agency managing Drupal sites already does this work — the problem is doing it for every client, every week, without missing one.
What Drubix does
General-purpose SEO and uptime tools don't know what a Drupal security advisory is. Drubix is built around exactly that.
Every advisory checked against your actual installed modules — a confirmed version match, not a guess.
See every site you manage in one place, sorted by what actually needs attention.
Every finding comes with the exact command to fix it — ready to run, not a link to research.
Slack, email, or webhook the moment an advisory affects a site you manage — filtered by severity, not spammy.
Branded PDF summaries you can send clients, showing exactly what their retainer is paying for.
Daily snapshots show whether a site's health is improving or degrading over time, not just today's status.
See how a site's security posture ranks against every other Drupal site on the platform.
Flags configuration changed directly on a live site that never got exported to your repository.
Gate a deploy pipeline on open findings — fail the build before a known vulnerability reaches production.
Catches a publicly exposed .git directory, .env file, or database backup — plus missing security headers.
Flags dangerous role permissions and file hardening gaps — the misconfiguration behind most real Drupal breaches.
One advisory hitting 15 sites shows as one incident, not 15 findings to click through — only possible multi-site.
Proactively flags known-risky modules before there's a CVE to match against — most contrib modules have no security team coverage at all.
A number you can put directly in a client report — computed automatically from data Drubix already has.
Cross-references CISA's exploited-vulnerability catalog — fix what's actually being attacked, not just what's rated severe.
How it works
Paste a URL. Drubix scans it immediately — no credentials needed for the first look.
For confirmed version accuracy, drop in a small Drupal module — one Composer require, one Drush command.
When an advisory affects a site you manage, you hear about it immediately — with the exact command to resolve it.
Pricing
Priced per monitored site, all core features included at each tier.
Start with a free scan — no credit card, no commitment.