January '10

03

Posted by

in Community

Comments: 1 Comment

Professional Security Audit

In the past, whenever we received security related questions and suggestions for Piwik, sent to our security@piwik.org address, we quickly reacted and released a fix in a new Piwik release. However, going forward, we want to be proactive, so we requested a professional and thorough review of our code base.

SektionEins, a leading software security company based in Germany, undertook the professional security review of the Piwik source code. Stefan Esser conducted the audit on the Piwik source code for 5 full days. Stefan then sent us all the details about what could be improved in Piwik regarding security (various recommendations, XSS, etc.). Anthon from the Piwik team then prepared fixes and improvements following the security audit, which were then released in Piwik 1.1.

We would like to give a huge thanks to SektionEins and Stefan Esser for their work and support to Piwik and the open source community. We are very happy with their service, and can only recommend all other open source projects (and of course any closed source softwares) to contract them for security audits, consulting and/or security training.

We also want to give credit to our sponsors who helped us cover the cost of the review.

You can also learn more about our continuous Security efforts in Piwik.

About author
piwik team member

Piwik 团队

Piwik 理念 «通过一个社区,创建先进的国际性开源网站分析平台,让每个用户完全控制自己的数据。»

如果可以,请您现在就为了 Piwik 的未来捐款,或者通过集资平台来赞助一个对您有用的新功能。

Like what you read?

Subscribe to our rss feed: Posts or you can Suggest a topic to write about in the blog or See list of Features

  1. May 26, 2011 9:58 pm

    wow you hit it on the dot will submit 2 stumbleupon

Leave a Reply

Post Comment