This project is not covered by Drupal’s security advisory policy.

Simplenews SQL Sanitize teaches Drush's sql:sanitize command how to clean up Simplenews newsletter subscriber data. If your site uses Simplenews, every subscriber's real email address lives in the database — and a copy of that database sanitized by Drush alone, pulled to a laptop for local development or pushed to a staging/dev site, carries all of those real addresses along with it. This module closes that gap: install it, and the next sanitize run anonymizes subscriber emails automatically, the same way Drupal core already anonymizes user accounts.

Features

  • Plugs into Drush's sql:sanitize command as a sanitize plugin — no separate command to remember; it runs as part of the sanitize you already run.
  • Anonymizes email addresses in Simplenews' own simplenews_subscriber and simplenews_subscriber_history tables, plus simplenews_stats_item from the optional Simplenews Stats module, mirroring how Drupal core rewrites users_field_data.mail to user+%uid@localhost.localdomain.
  • Anonymizes in place rather than truncating: subscriber rows are preserved, so newsletter admin views, subscriber counts, and stats pages still have realistic-shaped data to develop and test against — you just can't see anyone's real email address.
  • Truncates simplenews_mail_spool, the mail processing queue, rather than scrubbing it in place — its data column can hold a fully rendered message body, not just an address, and spooled entries are transient queue data.
  • Both behaviors can be disabled independently with --sanitize-simplenews-subscribers=no and --truncate-simplenews-mail-spool=no.
  • Works on MySQL/MariaDB, PostgreSQL, and SQLite.
  • Use this any time a production or production-adjacent database is copied somewhere less trusted: a developer's laptop, a shared staging server, a CI environment, or a client demo site.

Post-Installation

There's nothing to configure. Once enabled, the module registers itself with Drush's sanitize system automatically — the next time anyone runs drush sql:sanitize (or drush sql-sanitize) against a site with this module enabled, Simplenews data is sanitized as part of that run, alongside whatever core and any other installed sanitize-aware modules already handle. No new content type, no settings page, no permissions to grant.

Additional Requirements

  • Simplenews Stats is optionally supported: if it's installed, the subscriber email addresses it stores for click/open tracking are anonymized too — detected automatically, nothing to configure. Sites without it are unaffected.
  • If your site also uses Commerce, pair this with Commerce SQL Sanitize for the same treatment of order, address, and payment method data.

Similar projects

  • Simplenews Drush Sanitize addresses the same problem but was built for Drupal 7 and Drush's old hook-based sanitize system. It has a single 7.x-1.x-dev release, hasn't seen real activity in years, and isn't compatible with the plugin-based sql:sanitize used by modern Drush.
  • Commerce SQL Sanitize isn't a competitor — it's the direct inspiration for this module's approach, solving the identical problem for Commerce order/address/payment data instead of Simplenews subscribers.

Supporting this Module

No funding links at this time.

Community Documentation

No configuration is required — the examples below assume Simplenews (and optionally Simplenews Stats) is already enabled.

Run a sanitize and watch for the module's own lines in the output:
drush sql-sanitize
Look for "Sanitize Simplenews subscriber email addresses." and "Truncate the Simplenews mail spool." in the confirmation prompt, and "Simplenews subscriber emails sanitized." / "Simplenews mail spool truncated." in the success messages afterward.

If you want to run every other sanitize operation while skipping just this module's behavior, use these parameters:
drush sql-sanitize --sanitize-simplenews-subscribers=no --truncate-simplenews-mail-spool=no

Verify the result directly against the database:
drush sql-query "SELECT mail FROM simplenews_subscriber LIMIT 5"
Real addresses should now read like subscriber+42@localhost.localdomain, where 42 is that row's own ID — never a real inbox.

Roadmap

  • Drush 14, still under active development, replaces the sanitize plugin API with Symfony event listeners. Future support is tracked in #3 Work Item.
  • Testing enhancements are planned in #4 Work Item to cover all use-cases, including when Simplenews Stats is NOT enabled. The module correctly accounts for the use-case but lacks regression tests.
  • Drupal 12 compatibility is planned in #1 Work Item, with the goal of having Drupal 12 supported the day of the stable release.

Project information

Releases