Real Story Group. Make Better Technology Decisions.

Delivering fearless advice since 2001. Here's our story
What Real Independence means. Find Out

  • Schedule a Demo
  • Free Sample
  • Contact
  • Subscriber Login
  • Your cart is empty.
Sign up for our Newsletter
  • Home
  • Evaluation Reports
  • Premium Subscriptions
  • About
  • Blog
  • Buy Now
  • Recent Entries
  • Get Custom Feeds

 

 

 

Thomas Kas Thomas

Beware Drupal, Joomla! plug-in vulnerabilities

1-Mar-2010

Tags: Enterprise Collaboration & Social Software, Web Content and Experience Management, Open Source, Selecting Technology, Drupal, Joomla!, TYPO3

IBM has released its IBM Security Solutions X-Force 2009 Trend and Risk Report, and the news for users of popular WCM platforms Drupal, Joomla!, TYPO3, and WordPress is decidedly mixed.

According to IBM's research, while Apache and PHP account for only 0.4 percent and 0.6 percent (respectively) of total reported vulnerabilities, Drupal accounted for 2.7 percent and Joomla! accounted for 2.6 percent. TYPO3 and WordPress fared somewhat better, at 1.5 and 0.4 percent, respectively.

But the more ominous news has to do with patches for security problems involving plug-ins. A whopping 80 percent of the vulnerabilities reported for Joomla! plug-ins (against 13 percent for Drupal plug-ins) had no available security patches by year's end. That compares to 8 percent of Joomla! core system vulnerabilities that had no known patch, and 18 percent of Drupal core vulnerabilities with no patch. If you're a TYPO3 user, you'll find that 51 percent of plug-in vulnerabilities have no patch (versus just 5% of core system gotchas), while with WordPresss the unpatched plug-in flaws come to 57 percent, versus 13 percent for core.

Bottom line: Systems that are heavily reliant on plug-ins are more apt to have security vulnerabilities for which there is no known patch. Why is this?  Even frequently-used plug-ins are not always actively maintained and enhanced by their original developers.  Our Web CMS evaluation research cites some specific examples across several platforms. 

    Excerpt from the Drupal Evaluation

    Web Content Management Report looks at... Integrated Site Search in Drupal

    "The integrated full-text search functionality is adequate for searching text-based content, though file-based content is not indexed -- making Drupal arguably less useful for an intranet. The default search configuration has a basic search and an advanced search that can look for keywords, exact match phrases, and can restrict by content type. Searches tend to return too many results rather than too few. Note that the index is refreshed by a scheduled script running on the server, rather than every time content gets updated. On the whole, this is quite weak..."
    (p. 441)

    CMS Vendor Evaluations

    Learn the real strengths and weaknesses of major CMS vendors from around the world, in our Web Content and Experience Management research stream.

Tweet

close x

Free Sample Request

  Digital and Media Asset Management
  Document Management (ECM)
  Enterprise Collaboration & Social Software
  Enterprise Search
  Portals and Content Integration
  SharePoint Ecosystem
  Web Content and Experience Management
 Send me bi-weekly tips and insights from Real Story Group.
Your personal information, including your e-mail address, will be held in the strictest of confidence and will never be shared with anyone.

Subscriber Log In


Remember Me
Forgot password?


Not a subscriber?
Learn about our subscriptions

Research Mentioned in this Post

CMS Vendor Evaluations

Learn the real strengths and weaknesses of 35 major Web CMS products from around the world.

 | 

Our Newsletter

Get the Real Story bi-weekly.

Have Questions?

USA & Canada
+1 800 325 6190

UK
+44 (0) 20 3318 1911

International
+1 617 340 6464


All Other Inquiries

Our Customers Say

"I think The Web CMS Research is well worth it. Information is always key to good decisions; don't skip that step! It's also surprisingly well written and not as dry as you would expect. I have an IT background and also a writing (English Literature) background, so I very much appreciated the balance of charts, tech info, and plain-speaking, good old sentences!"

Paul Whittle, Web Manager, Memorial University

next More

Real Story Group

Follow us on:  RSS  |  Twitter  |  Facebook  |  YouTube

Evaluation Reports

  • Web Content and Experience Management
  • Digital and Media Asset Management
  • Enterprise Collaboration & Social Software
  • Document Management (ECM)
  • Portals and Content Integration
  • Enterprise Search
  • SharePoint Ecosystem

Premium Subscriptions

  • Research Streams
  • Advisory Papers
  • Vendors Evaluated
  • Schedule Analyst Consultation
  • Online Education
  • Configure a Subscription

About Us

  • Our Methodology
  • Our Team
  • Media
  • Customer List
  • Events
  • Consulting
  • Contact Us

Need Help?

  • Talk to an Expert
  • FAQs
  • Customer Support
  • Contact Sales Team
  • Help with your account

Copyright Real Story Group 2001 - 2012. All rights reserved.

  • Contact Us
  • Copyright Policy
  • Privacy Policy
  • Terms of Use

Log In

Remember MeForgot password?

close x
close x

All analyst firms claim to be independent or vendor-neutral. We're different.

Real Independence


Get the real story on commercial and open source tools from a firm that works only for you, the technology customer.

close x

Newsletter Signup

Thank you for signing up for The Real Story Group Newsletter. You will receive our monthly newsletter, plus updates with new information on the technology streams you have expressed interest in below.










Choose the streams that you’d like to receive updates for: