Content Security Audit full report showing PII Disclosure and Credentials Disclosure risk gauges both at low risk

This module is part of the AI module ecosystem and included in DXPR CMS.

Sensitive Data Leaks in Content Are Invisible Until They're Not

A support article accidentally includes a customer's email. A developer pastes an API key into a documentation page. A case study reveals a client's internal project name. These things happen, and by the time someone notices, the damage is done. This module scans every piece of content for security risks before they become incidents.

Content Security Audit full report showing PII Disclosure and Credentials Disclosure risk gauges both at low risk

You need AI Content Security Audit if

  • Your content includes real customer data, internal systems, or technical details that could leak
  • Compliance regulations (GDPR, HIPAA, SOC 2) require you to prevent PII disclosure in published content
  • Developers or technical writers contribute content that may contain credentials, API keys, or tokens
  • You want automated screening of content before publication, not manual review that misses things

What You Get

  • Risk score per page (0-100)

    Every content entity gets a security risk score per detection vector: 0 means no risk, 100 means critical. Displayed as a visual gauge so editors immediately see which pages need attention.

Content security audit risk gauge showing PII and Credentials Disclosure scores on a colour-coded scale from no risk to critical

  • Built-in detection for common leaks

    Ships with two security vectors ready to go:

    • PII Disclosure: names, addresses, phone numbers, SSNs, email addresses
    • Credentials Disclosure: API keys, passwords, tokens, database credentials
  • Custom security vectors

    Add your own detection vectors for organisation-specific risks: proprietary project names, internal URLs, partner data, anything your security policy requires.

  • Batch scanning for existing content

    Audit your entire content library to find pages that were published before security review was in place. Prioritise remediation by risk score.

Content security audit detailed results showing individual detection vectors with risk levels and findings per content page

  • AI Coding Assistant Integration

    Security audit analysis is available to AI coding
    assistants through the Analyze module's built-in
    Agent
    Skills
    file. Run
    drush analyze:setup-ai to enable, then ask
    naturally:

    • "Scan all content for security risks"
    • "Check if any pages expose PII or
      credentials"
    • "Run a security audit on all published
      articles"

    Compatible with Claude Code, Codex CLI, Gemini CLI,
    GitHub Copilot, Cursor, and other tools supporting the
    standard.

Getting Started

  1. Set up an AI provider at /admin/config/ai/providers
  2. Review security vectors at /admin/config/analyze/content-security-audit (or add custom ones)
  3. Enable the analyzer per content type at /admin/config/content/analyze-settings
  4. Open any content entity's Analyze tab to see risk scores

Prefer a turnkey demo site?

Spin up DXPR CMS: Drupal pre-configured with DXPR Builder, DXPR Theme, the full Analyze suite including AI Security Audit, and security best practices out of the box.

Get DXPR CMS »

Additional requirements

This module requires:

FAQ

What types of sensitive data does it detect?

The module ships with two built-in detection vectors: PII Disclosure (names, addresses, phone numbers, SSNs, email addresses) and Credentials Disclosure (API keys, passwords, tokens, database credentials). Each vector scores content from 0 (no risk) to 100 (critical). Custom vectors can be added for organisation-specific risks such as proprietary project names or internal URLs.

Does the security audit run automatically?

Scores are computed when you view the Analyze tab on a content entity or run a batch analysis. The module does not scan in the background unprompted; you trigger scanning either per-page or across your entire content library. Results are cached and only recomputed when content changes.

Is this module suitable for compliance requirements?

The module helps teams comply with GDPR, HIPAA, and SOC 2 requirements by screening content for personal data and credentials before publication. It does not replace a formal compliance programme, but it catches accidental disclosures that manual review routinely misses, especially across large content libraries.

Related Modules

  • Analyze - Required. Provides the plugin framework, Analyze tab, and batch processing this module extends
  • AI - Required. Supplies the LLM provider used for evaluating content against security vectors
  • Views Color Scales - Required. Renders colour-coded risk score columns in the security audit Views report
  • AI Content Marketing Audit - Sibling Analyze plugin that scores marketing effectiveness
  • AI Sentiments Analysis - Sibling Analyze plugin that measures tone, trust, and reading level
  • Analyze Broken Links - Sibling Analyze plugin that checks link health without AI

AI Content Security Audit is part of the Analyze suite included in DXPR CMS, a turnkey marketing CMS for Drupal that combines content analysis, a premium Drupal theme, and a drag-and-drop layout builder. See getting started or explore pricing.

Supporting organizations: 
Main sponsorship
AttachmentSize
security-audit-details.jpg96.04 KB
security-audit-gauge.jpg35.12 KB

Project information

Releases