What this solution does
SolverWeb Vulnerability Scanner monitors the security of installed Bitrix modules. The tool collects a list of all installed modules along with their identifiers and versions, then sends this data to the external SolverWeb API for analysis. The site source code is neither transmitted nor processed.
Before the first check, the administrator must provide consent. Until consent is granted, neither manual checks nor the daily agent will send requests. Individual modules can be excluded from the check if their data does not need to be transmitted.
Upon receiving the API response, the module displays a clear overview: the location of vulnerabilities, available patches, solutions removed from publication, modules not found in the Marketplace, and versions considered safe. Vulnerabilities are cross-referenced with the actually installed version to prevent false alarms caused by outdated records in the database.
The verification database is compiled from patch notes of solutions in the Marketplace and official sources from 1C-Bitrix, including the Center for Information on Required Updates.
The module cross-references installed solutions against a registry of vulnerabilities in third-party products available at 1c-bitrix.ru/vul_dev. This registry contains information on affected modules, unsafe versions, and developer recommendations. When a vulnerability is detected, the system generates a notification within the Bitrix administration panel. For sending alerts via email or Telegram, the module utilizes solverweb.logger. Users must enable the vulnerability notification option in Logger settings and configure the desired communication channel. Once configured, warnings are routed to the VulScanner space and processed according to the rules defined in Logger.
If “SolverWeb: Vulnerability Scanner” fits the task, General iT can install the module, configure it and verify the result in the project.