Sherlock Logo Sherlock

Security scanner and monitor to keep your site secure.

Checks for security vulnerabilities in your site and tells you how to fix them.

Receive an instant email notification if your site fails a security scan.

Easily schedule security scans to automatically run daily or weekly.

Sherlock is a security scanner and monitor to keep your site and CMS secure. An essential plugin for any site and CMS that stores sensitive or important data.

Sherlock Scan

Features #

Security Tests
Sherlock checks for security vulnerabilities on your site such as folder and file permissions, cross-origin resource sharing, cross-site request forgery, HTTP response headers, etc. and tells you how to fix them.

Encrypted Connections
Sherlock ensures that your site is forcing encrypted connections both on the front-end and back-end so as to secure user data and credentials.

CMS Configuration
Sherlock checks all of the Craft CMS configuration settings on your site to ensure that they are properly configured and safe to use in a production site.

Critical Updates
Sherlock runs a series of tests to ensure that your site is correctly updated and will warn you about critical security updates to the CMS, plugins and the PHP version running on your server.

Email Notifications
Receive an instant email notification if your site fails a security scan. A control panel alert in the CMS also notifies you of a failed security scan.

Scheduled Scans
Easily schedule security scans to automatically run daily or weekly on your site with cron jobs.

Scan Details & History
View the full details of your site’s last scan, including failed tests and warnings. For each test you can view more details and relevant documentation. You can also view the full security scan history of your site over time.

License #

This plugin requires a commercial license purchasable through the Craft Plugin Store. The license fee is $99 plus $49 per subsequent year for updates (optional).

Requirements #

This plugin requires Craft CMS 3.0.0 or later.

Basic Usage #

Getting Started #

Install the plugin from the Craft Plugin Store in your site’s control panel or manually using composer.

composer require putyourlightson/craft-sherlock

Once installed, visit the Sherlock page in the control panel to run your first security scan.