I think it should be possible for modules to add more permissions that they consider to be "permissions that will own the site.".

By default security_review only includes permissions from core, but it should provide a way for other modules to declare permissions that are important. Since this would be additive to the default list I don't see a way for a malicious module to screw with the report as a result of this hook.

Comments

smustgrave’s picture

Issue summary: View changes
Status: Active » Closed (outdated)

As Drupal6 has been EOL https://www.drupal.org/about/drupal6-eol closing as outdated