Drubix

Drupal security & health monitoring

Know about a Drupal vulnerability before your client does.

Drubix watches every site your agency manages, checks it against Drupal.org's security advisories, and tells you exactly what to run to fix it — before it becomes an incident call.

No credit card. Paste a URL, get a report in under a minute.

$ drubix scan client-portal.example.com

Drupal 10.1.2 detected · 34 modules found

Checking against 1,842 known advisories…

HIGHWebform — Cross-site scripting — SA-CONTRIB-2026-014

Installed: webform 6.2.1 · Fixed in: 6.2.3

→ composer require drupal/webform:^6.2.3

✓ 33 other modules clear

The problem

Checking advisories by hand doesn't scale past a handful of sites

Every agency managing Drupal sites already does this work — the problem is doing it for every client, every week, without missing one.

~40/mo
Drupal core and contrib advisories published, each needing a manual check against every client site
1-of-many
A vulnerable version is rarely the whole story when you're juggling dozens of sites on different patch cadences
after the fact
Most agencies find out a site was vulnerable when something breaks, not when the advisory was published

What Drubix does

Built specifically for Drupal, not bolted onto a generic scanner

General-purpose SEO and uptime tools don't know what a Drupal security advisory is. Drubix is built around exactly that.

Security matching

Every advisory checked against your actual installed modules — a confirmed version match, not a guess.

Multi-site dashboard

See every site you manage in one place, sorted by what actually needs attention.

Remediation included

Every finding comes with the exact command to fix it — ready to run, not a link to research.

Real-time alerts

Slack, email, or webhook the moment an advisory affects a site you manage — filtered by severity, not spammy.

White-label reports

Branded PDF summaries you can send clients, showing exactly what their retainer is paying for.

Historical trends

Daily snapshots show whether a site's health is improving or degrading over time, not just today's status.

Cross-site benchmarking

See how a site's security posture ranks against every other Drupal site on the platform.

Config drift detection

Flags configuration changed directly on a live site that never got exported to your repository.

CI/CD integration

Gate a deploy pipeline on open findings — fail the build before a known vulnerability reaches production.

Attack surface scanning

Catches a publicly exposed .git directory, .env file, or database backup — plus missing security headers.

Permissions & hardening audit

Flags dangerous role permissions and file hardening gaps — the misconfiguration behind most real Drupal breaches.

Blast-radius incidents

One advisory hitting 15 sites shows as one incident, not 15 findings to click through — only possible multi-site.

Unmaintained module flagging

Proactively flags known-risky modules before there's a CVE to match against — most contrib modules have no security team coverage at all.

Mean time to patch

A number you can put directly in a client report — computed automatically from data Drubix already has.

Known-exploited prioritization

Cross-references CISA's exploited-vulnerability catalog — fix what's actually being attacked, not just what's rated severe.

How it works

Set up in minutes, not a sprint

Add a site

Paste a URL. Drubix scans it immediately — no credentials needed for the first look.

Install the connector (optional)

For confirmed version accuracy, drop in a small Drupal module — one Composer require, one Drush command.

Get alerted with a fix

When an advisory affects a site you manage, you hear about it immediately — with the exact command to resolve it.

Pricing

Flat pricing per site. No add-ons to itemize.

Priced per monitored site, all core features included at each tier.

$0
Free scan — unlimited one-off passive scans
$10
Monitored — per site / month, weekly monitoring + alerts
$16
+ Connector — per site / month, confirmed accuracy + reports

See what's actually running on your client sites

Start with a free scan — no credit card, no commitment.