Smart 404 closes the gap between "there are 404 errors on my site" and "I've fixed them." It automatically logs every 404 response, aggregates hits per path, and presents them in a clean admin overview where site builders can create redirects with a single click, directly from the Drupal backend, without touching server logs, analytics dashboards, or the command line.
The module integrates with the standard Redirect module for redirect creation and installs it automatically as a hard dependency, so you get a complete solution out of the box. It also optionally integrates with the Search 404 module to ensure 404s are logged even when Search 404 replaces the error page with search results or a redirect.
Features
- Automatic 404 logging. Every 404 response is captured via a Symfony event subscriber. Hits are aggregated per normalized path: no duplicate rows, no table bloat.
- Path normalization. Paths are lowercased, trailing slashes stripped, and query strings removed before storage, so
/Over-Ons/and/over-onscount as one entry. - Multi-domain aware. On a multi-domain or multi-site install, the same path on two different hosts is logged as two separate entries, with a Host column and filter in the overview.
- Admin overview. Filterable, paginated table showing path, hit count, first seen, last seen, referer source, and bot indicator. Bulk actions: create redirects, ignore, or delete.
- One-click redirect creation. Form pre-filled with the source path and the best matching existing alias as a destination suggestion.
- Intelligent path suggestions. The suggestion engine queries the path alias table using a fragment match and ranks candidates by Levenshtein distance. Results are cached per path for one hour.
- Bulk redirect form. Select multiple 404 paths and create all redirects on one confirmation page, with per-row destination editing.
- Per-day hit timeline. The 404 detail page shows the last 30 days of hits, so you can tell a slow trickle from a recent spike.
- Drush commands.
smart404:list,smart404:cleanup, andsmart404:redirectcover the same actions from the command line. - Bot detection. User agents are matched against a pattern list to flag likely bot/crawler traffic. Only a bot/not-bot flag is stored, never the raw user-agent string. Bot traffic can be hidden from the overview or excluded from logging entirely.
- Ignore patterns. Glob patterns (e.g.
/wp-admin/*,*.php) exclude known false-positives from ever being logged. Sensible defaults are included. - Configurable retention. Automatic cleanup via cron: delete records older than N days and enforce a maximum record count. Zero configuration required to get started.
- GDPR-aware by design. No IP addresses stored, no external services, no tracking. External referers are stored as domain-only. Raw user-agent strings are discarded immediately after checking against the bot pattern list.
- Status tracking. Each path has a status: New, Ignored, or Resolved. Resolved paths show the linked redirect entity ID.
- Permission-based access. Granular permissions for viewing the log, managing it (bulk actions), creating redirects, and managing settings.
- Search 404 integration. When the Search 404 module is installed, Smart 404 can log 404s at the exception level before Search 404 converts the response into a redirect or a search-results page so no 404 is ever missed in your statistics.
Use cases
- A content editor renames a page: the old path quickly appears in the 404 overview and can be redirected in seconds.
- A site migration leaves dozens of broken internal links: bulk-create redirects from one screen without opening a spreadsheet.
- External sites link to outdated URLs: referer information shows exactly where the broken links come from so you can notify the source.
- A developer wants to monitor 404 trends without granting server access to non-technical staff.
Why not just use the Redirect module?
The Redirect module solves the problem once you already know about it. Smart 404 helps you discover the problem in the first place. Without a logging layer, you need to download server logs, run grep commands, or pay for analytics tools to find out which paths are returning 404s. Smart 404 eliminates that gap: log in to the Drupal backend, open the 404 overview, and start fixing. No technical knowledge required.
Requirements
- Drupal 10.3 or higher, or Drupal 11
- PHP 8.1 or higher
- Redirect module ≥ 1.9 (installed automatically as a Composer dependency)
Installation
Install via Composer. The Redirect module is pulled in automatically:
composer require drupal/smart_404 drush en smart_404 -y drush cr
Or enable via the UI at Manage > Extend > Smart 404. Drupal will offer to install the Redirect module at the same time if it is not yet active. No manual database setup is required.
Configuration
After installation, visit Manage > Configuration > System > Smart 404 to adjust:
- Retention period. How many days to keep records (default: 90 days, based on last-hit date).
- Maximum records. Cap on total stored paths (default: 10,000). Oldest records are removed first when the cap is exceeded.
- Strip query string. Normalize
/search?q=aand/search?q=bto the same path entry (default: enabled). - Log bot traffic. Disable to exclude known crawlers and scanners from the log entirely (default: enabled; bots are hidden in the overview by default).
- Log referers. Disable to store no referer information at all (default: enabled).
- Ignore administrators. Skip logging 404s triggered by users with the administer site configuration permission (default: enabled).
- Search 404 integration. Enable under the Integrations section. Only available when the Search 404 module is installed. Ensures all 404s appear in the log, even when Search 404 intercepts them.
The Ignore patterns tab manages a list of glob patterns for paths that should never be logged. The 404 log overview is available at Manage > Reports > 404 Log.
Frequently asked questions
Does Smart 404 store IP addresses or personal data?
No. IP addresses are never stored at any point. User-agent strings are matched against a pattern list to flag likely bot traffic; only a bot/not-bot flag is stored, and the raw string is discarded immediately. External referers are stored as domain-only (e.g. https://example.com), not as full URLs. The module has no connection to any external service. It is designed to be GDPR-compliant out of the box, though you should always verify compliance for your specific legal context.
Will logging 404s slow down my site?
The performance impact is minimal. Each unique 404 path triggers a single database UPSERT. Repeated hits on the same path within the same request are deduplicated in memory. If the configured record cap has been reached, logging is skipped entirely (checked via a short-lived cache). The event subscriber runs at priority -100, after all other response processing is complete.
My site gets thousands of bot 404s. Will this fill up my database?
Smart 404 has three safeguards: (1) enable "Do not log bot traffic" to discard all recognized bot hits before they reach the database; (2) add glob patterns like /wp-admin/* or *.php to the ignore list, useful defaults are already included; (3) the configurable maximum record count prevents unbounded table growth regardless of traffic volume. Bot hits that are logged are hidden in the overview by default.
Does Smart 404 work on multilingual sites?
Yes. Paths with language prefixes (e.g. /nl/over-ons, /en/about-us) are logged and normalized as separate entries. Language context is detected when creating redirects and passed to the Redirect entity, so redirects apply correctly per language.
What happens when I uninstall Smart 404?
The smart_404_log table and all module configuration are deleted. Redirects that were created via Smart 404 are not deleted. They belong to the Redirect module and remain active. If you also want to remove those redirects, do so manually via Manage > Configuration > Search and metadata > URL redirects before uninstalling.
Does Smart 404 work with multi-domain setups?
Yes, as of version 1.2. The log is segmented per host: the same path /about on two different domains is stored as two separate entries. The admin overview has a Host column and a "Host contains" filter. Records logged before upgrading to 1.2 are kept as a single legacy entry with an empty host.
How does the module prevent redirect loops?
Before a redirect is saved, it is checked against several conditions: the source and destination cannot be the same path (after normalizing case, a trailing slash, percent-encoding, and dot-segments); the destination cannot already resolve, through one or more existing redirects, back to the source; and the source path is re-checked against the live routing table to make sure it hasn't since become a real page. Each of these is a hard validation error, not a dismissable warning: the redirect is not created until it is fixed.
Can I export or import the 404 log?
Not yet. The log is stored in a custom database table, not as Drupal config. Views integration (which would also enable custom exports) is still planned for a future release; in the meantime, the smart404:list Drush command can print the log to the command line, which covers simple export needs.
Roadmap
Version 1.0
- Automatic 404 logging with path normalization and bot detection
- Admin overview with filters, pagination, and bulk actions
- One-click and bulk redirect creation via the Redirect module
- Intelligent path suggestions (alias fragment match and Levenshtein ranking)
- Ignore patterns for known false-positives
- Configurable retention via cron
- GDPR-aware: no IP storage, bot flag instead of raw user agents, domain-only external referers
- Optional Search 404 integration: log 404s even when Search 404 intercepts them
Version 1.1
- Drupal 12 compatibility
- Fixed "Strip query string" setting having no effect
- Open-redirect protection on the redirect-creation forms; dependency-injection and coding-standards cleanup ahead of the security advisory application
Version 1.2 (current)
- Multi-domain awareness: log and display the host alongside the path, with a Host column and filter in the overview
- Per-day hit timeline on the 404 detail page
- Drush commands:
smart404:list,smart404:cleanup,smart404:redirect - Extensive security hardening across the redirect-creation and validation code paths: stronger redirect-loop detection, stricter internal-destination validation, a new "Manage Smart 404 log" permission gating the overview's bulk actions, and tightened permission checks on the redirect-creation routes
- Completed drupal.org's security advisory policy review (#3611786): Smart 404 is now covered by Drupal's security advisory policy
- Numerous smaller correctness and documentation fixes; see CHANGELOG.md for the full list
Planned
- Views integration: use the log table as a Views data source for custom reports and exports
- CSV export from the overview table
- Weekly email digest: summary of new 404s since the last report
- Admin dashboard block: top-5 newest 404s in the main admin panel
Built by a human using an AI assistant.
This module was developed with substantial assistance from AI coding tools, under human review and testing for every change.
Project information
- Project categories: Administration tools, Search engine optimization (SEO), Site structure
- Ecosystem: Redirect, Search 404
30 sites report using this module
- Created by mookum on , updated
Stable releases for this project are covered by the security advisory policy.
Look for the shield icon below.
