wappalyzer

Drupal

Drupal is an established open-source content-management system used for complex, content-heavy sites including many government and enterprise deployments. It is detected from generator meta tags, characteristic paths and asset fingerprints.

Unpatched Drupal cores and contributed modules have been the root of serious mass-exploitation events. A Drupal detection is a cue to check the version and look for signs of compromise in the scanned page.

Public scans
12,952
Category
wappalyzer
Co-detected technologies
14
Versions observed
5

Commonly deployed alongside Drupal

Of the 12,952 public scans where Drupal was detected, these are the technologies most often present on the same site. The share is the percentage of Drupal sites that also ran each one.

TechnologyCategoryShare of Drupal sites
MetaGeneratormiscellaneous
74.7%
PHPwappalyzer
62.79%
HSTSwappalyzer
47.48%
jQuerywappalyzer
42.14%
Google Analyticswappalyzer
38.65%
X-UA-Compatiblemiscellaneous
35.71%
Scriptmiscellaneous
28.66%
Google Tag Managerwappalyzer
27.77%
Open-Graph-Protocolmiscellaneous
27.11%
Google-Analyticsmiscellaneous
26.63%
Cloudflarewappalyzer
18.01%
JQuerymiscellaneous
13.9%
Cloudflare Bot Managementwappalyzer
13.38%
PoweredBymiscellaneous
13.36%

How ScanMalware detects Drupal

Drupal is detected by analysing the response headers, HTML markup, JavaScript runtime and asset URLs captured when ScanMalware loads the site in a real headless browser.

From any scan you can pivot into related signals — JARM TLS fingerprints, ASN ownership and BGP routing, certificate history, JavaScript analysis and the overall security verdict — to understand not just that Drupal is present, but how it is being used. Open the full search interface for Drupal

Recent public scans featuring Drupal

A rolling sample of recent public scans where Drupal was detected. Listing a site here is not a safety judgement — open a scan to see its full verdict.

SiteScanned
UNEP - UN Environment Programme
https://unep.org
2026-09-18
chatarra de carros ¿dónde compran carros para yonke? - 2024 mustang wallpaper
https://2024mustangwallpaper.pages.dev/post/chatarra-de-carros/
2026-09-17
Home | Geophysical Institute
https://gi.alaska.edu
2026-09-17
ITIE Moçambique | Iniciativa de Transparência na Indústria Extractiva
https://itie.org.mz
2026-09-17
Startseite - Nürtinger Zeitung - ntz.de
https://ntz.de
2026-09-17
Golfmagic
https://cdn.golfmagic.com
2026-09-17
The Best Personal Lubricants for Every Need | Astroglide
https://www.astroglide.com
2026-09-17
Home | Superior Court of California | County of Contra Costa
https://contracosta.courts.ca.gov
2026-09-17

Frequently asked questions about Drupal

Does using Drupal mean a website is unsafe?
No. Drupal is a stack component, not a verdict. ScanMalware scores the whole page — its scripts, redirects, certificates, threat-intelligence matches and behaviour — so a site using Drupal can be perfectly safe or actively malicious.
How many sites using Drupal has ScanMalware scanned?
Drupal has been detected in 12,952 public scans on ScanMalware.com. Each scan is a real headless-browser visit, and the figure updates as new URLs are submitted.
What technologies are commonly used with Drupal?
Across scanned sites, Drupal is most often seen alongside MetaGenerator, PHP and HSTS. The full co-occurrence breakdown is listed on this page.

Browse all profiled technologies on the technology index, or scan a URL to see its full stack.