Get the real story via our bi-monthly newsletter

Search

    4
    0

rss

Send to a colleague

Home > Commentary > Trends Archive > Quick: what do Joomla!, Drupal, and WordPress have in common?

Browse TrendWatch Blog

Recent Blog Entries

The Complete Archive

Trends by Vendor


TrendWatch by Channel

Web Content Management Trends

Enterprise Portals Trends

ECM Trends

Web Analytics Trends

Enterprise Search Trends

SharePoint Trends

Digital & Media Asset Management Trends

XML & Component Content Management Trends

E-mail Archiving & Management Trends

Enterprise Social Software Trends


Report Excerpt

The Web CMS Report 2009 looks at... Joomla!

"The types of users are fixed and there is no way to customize users and roles according to your specific needs. You are locked into the hierarchy. This kind of security implementation works find for small publishing operations, but is limiting for large sites who may want to have their own classes and roles for users. "

(p. 652)

More about The Web CMS Report 2009

Our customers say

"This excellent report has saved weeks of work reviewing the market place to enable a tender to be sent out to just a handful of potential vendors in record time. Well done.
- - Martin Beake,
ITT Consultant, 2Sys Limited, Malmesbury, UK

NEW at CMS Watch

The SharePoint Report 2009 The SharePoint Report 2009: This report will help your team decide whether and where and when to apply SharePoint to your information management problems.... Read more
Evaluating Native SharePoint Services SharePoint Online Education Course: This course will enable you to assess whether, where, and how to use SharePoint... Read more
The Web CMS Report 2009 The Web CMS Report 2009: In its 15th edition, this report evaluates 42 web content management systems and vendors... Read more

 

TrendWatch Blog

Quick: what do Joomla!, Drupal, and WordPress have in common?

18-Aug-2008

Big Blue recently released its IBM Internet Security Systems X-Force 2008 Mid-Year Trend Statistics report, and it contains more than a few eyebrow-raisers. For example: Web-application-based security vulnerabilities have begun to outnumber reports involving conventional viruses and trojans (of the kind that target the operating system). We're now at the point where 51 percent of newly discovered software vulnerabilities depend in some way on web-page interactions.

Also, there's been a sharp surge in the number of vulnerabilities that involve SQL injection (as opposed to cross-site scripting). Meanwhile, the use of infected image files (.gif or .jpg) as a way to inflict mayhem is on the decline.

What really got my attention, though, is the new Top Ten list of vendors with the most vulnerability disclosures. Normally you would expect Microsoft to be at the top of that list (I would, at least). Instead, it's at Number 3, behind Apple and... Joomla!. Fortunately, Joomla! can be secured, but it's quite possible that many novice Joomla! installers do not.

Numbers 8, 9 and 10 are interesting, as well: Drupal, WordPress, and Linux.

The finding that no fewer than four of the top ten vendors with the most reported vulnerabilities are open-source projects is, at first blush, quite striking. But the results should be viewed with caution. In part, the rankings reflect a recent change in IBM's data-gathering methodology (which the report's authors are quick to point out). Another important caveat is that the numbers are not normalized against adoption rates or installed seats or any other usage metrics. They're based on raw numbers.

It's worth remembering, too, that open source projects are extraordinarily open about security vulnerabilities. Hence you would expect a comparatively high rate of reporting for an open-source product. Finding, publishing, and fixing security vulnerabilities is something the open-source community has gotten quite good at, particularly in the Linux world, where every line of code for the entire operating system (including all encryption routines, random-number-generating code, and so on) is available free for the downloading. Security flaws in Linux tend to be found and corrected with astonishing alacrity.

On the other hand, it's striking that three of the Top Ten contenders on IBM's security worry-list have PHP in common. You can read whatever you want to into that, I suppose. I'm not a PHP expert, but I'm enough of a web developer to know that languages don't create security problems; programmers do.

If you have the time and the inclination, download the IBM report. At 85 pages, it' a well-worthwhile lunch-hour read, if you care about web-app security ... as I think we all should.

- Submitted by: Kas Thomas, Analyst

All CMS Channel Trends

Join the conversation

Digg This! Search Technorati Tag it on Del.icio.us



Get a Free Sample

Wondering about CMS Watch research? Sign up to receive free samples of any of our products.




What we do

CMS Watch™ evaluates content-oriented technologies, publishing head-to-head comparative reviews of leading solutions. What makes us special?

  • Our critical analysis exposes product weaknesses as well as strengths
  • We deliver unrivaled technical depth and comprehensive project advice
  • Our research is led by international topic experts
  • We only work for buyers -- never for vendors

Contact us

CMS Watch

info@cmswatch.com

18113 Town Center Drive, Ste 217

Olney, MD USA 20832

1 800 325 6190 (customer service)

+1 617 763 5336 (int'l customer service)

Fax: +1 214 242 3048