Ross ROSS = Recommend OSS · open-source software intelligence for agents

SamJoan/droopescan

A plugin-based scanner that aids security researchers in identifying issues with several CMSs, mainly Drupal & Silverstripe. observed · 2026-08-28

github.com/SamJoan/droopescan · HTML · AGPL-3.0 (copyleft) observed · 2026-08-28

Health v2 · maintenance only

32/100

  • Activity 0
  • Release rhythm 35
  • Longevity 100

Flags: no_releases

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 4333
  • days_rel: n/a
  • days_push: 957
  • n_releases_24m: 0

Full methodology

Adoption not part of the score

1445 stars · 273 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

Droopescan is a plugin-based command-line scanner that helps security researchers identify the CMS, version, plugins, themes, and interesting URLs of target websites. It primarily supports Drupal and SilverStripe, with WordPress support and partial support for Joomla and Moodle.

Use cases

  • identify which CMS a website is running
  • enumerate Drupal modules and themes on a target site
  • fingerprint the version of a Drupal or Silverstripe installation
  • find interesting URLs like admin login pages and changelog files during a pentest
  • audit my own CMS site for exposed plugin directories
  • scan multiple CMS sites from a list of URLs

When to choose

  • you need CMS-specific fingerprinting for Drupal or SilverStripe
  • you are a security researcher doing authorized reconnaissance of CMS-based sites
  • you want a scriptable CLI scanner that integrates into pentest workflows

When to avoid

  • you need a general-purpose web vulnerability scanner like a full DAST tool
  • you require active exploitation or automated vulnerability correlation - droopescan only enumerates, correlation is manual
  • you need support for CMSs beyond the ones listed, or deep Joomla/Moodle scanning
  • scanning targets without explicit authorization - doing so is illegal

Facets

cli-tool · maturity maintenance

security vulnerability-scanning penetration-testing web-scraping security penetration-testing web-development developer-tools python cli windows cms-scanner drupal silverstripe wordpress joomla moodle security-research reconnaissance plugin-based linux macos

1 source

Member repositories

RepositoryRoleHealth v2
SamJoan/droopescanmain32

For agents

markdown · JSON · MCP: product_card(name="SamJoan/droopescan")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem