Drupal Approved Modules

The School of Arts and Sciences Information Security and Unix Systems regularly audits Drupal modules to ensure security and stability. Before modules can be installed on our production environments they must be reviewed by information security staff. While this review is not a surefire guarantee of security, it does insure a certain degree of safety in the module code. Modules are examined for compliance with the Drupal secure coding guidelines as well as for common web application vulnerabilities (Cross Site Scripting, SQL injection, authentication bypass, remote code execution, file inclusion, information disclosure, etc.). Note that some modules are approved for use only with certain patches applied that address known vulnerabilities. The following are a list of modules which have been audited by the ISUS group:

Drupal 6

Drupal 5

Please note that every effort is made to keep this list current, however, module bug fixes and updates may be made after a review is complete. In the case where a newer version of the module has been released, the revision must also be reviewed before it can be recommended as it is possible for new security vulnerabilities to be introduced as part of a fix or feature addition.