Skip to main content

A plugin-based scanner that aids security researchers in identifying issues with several CMSs, mainly Drupal & Silverstripe.

Project description


  • Miscelaneous improvements.


  • Add new SS version.
  • Improved release process to allow the releasing from branches instead of only allowing releases from ‘development’.


  • Update SS to version 3.1.10.
  • Remove unnecessary files.
  • Improve plugin lists.


  • Improve documentation.
  • Add SS Release Candidates.


  • Added support for Drupal 8.x.
  • Usability improvements.
  • Add flag for not following redirects.


  • Improved SS detection for new reported bug.
  • Improve stats.
  • Remove relative redirects or same-site redirects.


  • Support for SS 3.9.
  • Remove super annoying warning by urllib3.
  • Usability improvements.
  • Add integration tests which should pick up on most issues.


  • Add PyPI support.
  • Add support for virtualenv.
  • Add “graceful” handling of SIGINT.
  • Documentation improvements.


  • Improved SS scanning (particularly plugin scanning) a great deal.
  • Added ‘interesting module urls’ for SS.
  • More documentation.
  • Internal tidy-up.


  • Added support for interesting module urls.
  • Add more documentation.


  • Update databases.
  • Improve drupal detection.
  • SilverStripe improvements.
  • Massive internal rework.


  • Add python 3 support.
  • More documentation.
  • General tidy up of the code.
  • Database updates.
  • Improved detection for SS modules.
  • Fixed memory leak which was showing up after scanning more than 40.000 websites.
  • Improved output.
  • Added travis support.
  • General bug fixes.

  • Database update. Drupal 7.33 & SS 3.1.7-rc have been released.


  • Add global per-site timeout.
  • Add functionality for logging standard errors to a file.


  • Add better handling for websites with fake changelogs, but still utilize them to narrow down when reasonable.
  • Deal with websites that always respond with 200 OK, even on not found pages. Add heuristic test to differentiate from real 200 OK responses.
  • Misc fixes.


  • Improved accuracy for druppagedon as far as possible.
  • Fixed aesthetic issues with JSON output.
  • Fixed issues with redirects on non-cms websites.


  • Added timeouts to prevent hanging on massive scans.
  • Avoid unnecessarily discarding connections due to a low max http pool limit.


  • Improve error handling.
  • Final release before stable.


  • Improve documentation.


  • Add new drupal version so that fully patched up versions of Drupal get detected properly.


  • Fix output issue.


  • Added JSON output.
  • Added multi-threaded multi site scanning.
  • Improved output.


  • Removed DNN.
  • Fixed SS updating process.
  • Fixed bug on display of loading bar.
  • Tag release.


  • Released beta of version 1.x.
  • Vastly improved version detection and database handling.

Project details

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Files for droopescan, version 1.22.0
Filename, size File type Python version Upload date Hashes
Filename, size droopescan-1.22.0-py2.py3-none-any.whl (241.1 kB) File type Wheel Python version 2.7 Upload date Hashes View
Filename, size droopescan-1.22.0.tar.gz (202.0 kB) File type Source Python version None Upload date Hashes View

Supported by

Pingdom Pingdom Monitoring Google Google Object Storage and Download Analytics Sentry Sentry Error logging AWS AWS Cloud computing DataDog DataDog Monitoring Fastly Fastly CDN DigiCert DigiCert EV certificate StatusPage StatusPage Status page