Formerly CMS Watch. Here's our story
What Real Independence means. Find Out
Kas Thomas
1-Mar-2010
Tags: Enterprise Collaboration & Social Software, Web Content Management, Open Source, Selecting Technology, Drupal, Joomla!, TYPO3
IBM has released its IBM Security Solutions X-Force 2009 Trend and Risk Report, and the news for users of popular WCM platforms Drupal, Joomla!, TYPO3, and WordPress is decidedly mixed.
According to IBM's research, while Apache and PHP account for only 0.4 percent and 0.6 percent (respectively) of total reported vulnerabilities, Drupal accounted for 2.7 percent and Joomla! accounted for 2.6 percent. TYPO3 and WordPress fared somewhat better, at 1.5 and 0.4 percent, respectively.
But the more ominous news has to do with patches for security problems involving plug-ins. A whopping 80 percent of the vulnerabilities reported for Joomla! plug-ins (against 13 percent for Drupal plug-ins) had no available security patches by year's end. That compares to 8 percent of Joomla! core system vulnerabilities that had no known patch, and 18 percent of Drupal core vulnerabilities with no patch. If you're a TYPO3 user, you'll find that 51 percent of plug-in vulnerabilities have no patch (versus just 5% of core system gotchas), while with WordPresss the unpatched plug-in flaws come to 57 percent, versus 13 percent for core.
Bottom line: Systems that are heavily reliant on plug-ins are more apt to have security vulnerabilities for which there is no known patch. Why is this? Even frequently-used plug-ins are not always actively maintained and enhanced by their original developers. Our Web CMS evaluation research cites some specific examples across several platforms.
Web Content Management Report looks at... Page Generation in TYPO3
"Natively, the product does not always output clean, friendly HTML. In particular, you may need to remove table-based markup..."
(p. 554)
Learn the real strengths and weaknesses of major CMS vendors from around the world, in our Web Content Management research stream.
Learn the real strengths and weaknesses of forty-four major Web CMS vendors from around the world.
Get the Real Story bi-weekly.
USA & Canada
+1 800 325 6190
UK
+44 (0) 20 3318 1911
International
+1 617 340 6464
All Other Inquiries
"I've seen a lot of basic vendor comparison guides, but none of them come close to the technical depth, real-life experience, and hard-hitting critiques that I found in the Search & Information Access Research. When I need the real scoop about vendors, I always turn to the Real Story Group."
Alexander T. Deligtisch, Co-founder & Vice President, Spliteye Multimedia
Copyright Real Story Group 2001 - 2012. All rights reserved.
All analyst firms claim to be independent or vendor-neutral. We're different.
Get the real story on commercial and open source tools from a firm that works only for you, the technology customer.
Thank you for signing up for The Real Story Group Newsletter. You will receive our monthly newsletter, plus updates with new information on the technology streams you have expressed interest in below.