Drupal Scanner — Core Version and Module Exposure
This detects a Drupal installation from the outside — core version and the modules it can identify — and checks what it finds against known vulnerabilities. Drupal powers a great many institutional and government sites, which tend to be long-lived, carefully built, and then left largely alone for years.
When it helps
Because Drupal's history includes vulnerabilities severe enough to be mass-exploited within hours of disclosure, against sites whose operators had every intention of patching promptly. The window is genuinely that short. Knowing your version from the outside, the way a scanner sees it, is what lets you answer "are we affected" immediately rather than after an inventory exercise you do not have time for.
Worth running automatically
The pattern is the same as WordPress and the urgency is higher. Your site does not change; the list of known vulnerabilities does, and it does so on someone else's schedule. A quarterly review is not fast enough for a vulnerability that is exploited within a day of disclosure. Scheduled scanning is what turns "we should check whether that advisory applies to us" into an answer that is already waiting when the advisory lands.
What you get out of it
An immediate answer to whether a disclosure affects you, from the outside. For a platform with a history of same-day mass exploitation, the speed of that answer is the control.