Content Management Systems (CMSs) power millions of websites worldwide, making them one of the most common ways to publish content online. Because many CMS users have limited cybersecurity expertise, the security protections enabled by default can play an important role in reducing risk.
In a study published today, Comparitech researchers took a look at four of the most popular open-source CMSs (WordPress, Drupal, Joomla, and Ghost), to determine which has the strongest out-of-the-box security. The CMS platforms were assessed immediately following installation to determine their secure-by-default posture, with the assessment considering browser security controls, information disclosure, authentication securiy, and API and enumeration exposure.
Key findings include:
- WordPress had the weakest out-of-the-box security protections, with a score of 8 out of 100
- Drupal achieved the highest overall score (27.1 out of 100) – note that none of the tested CMSs provided a particularly strong security posture immediately after installation
- Joomla has had the greatest number of disclosed vulnerabilities in the past five years
- Drupal recorded the highest number of high- and critical-severity core vulnerabilities between 2021 and 2025
- WordPress has the largest extension ecosystem, which may increase exposure to security risks associated with third-party plugins
For full details, please see the research here: https://www.comparitech.com/news/which-cms-platforms-provide-the-strongest-out-of-the-box-security/
Related
This entry was posted on August 12, 2026 at 2:49 pm and is filed under Commentary with tags Comparitech. You can follow any responses to this entry through the RSS 2.0 feed.
You can leave a response, or trackback from your own site.
Which CMS platforms provide the strongest out-of-the-box security?
Content Management Systems (CMSs) power millions of websites worldwide, making them one of the most common ways to publish content online. Because many CMS users have limited cybersecurity expertise, the security protections enabled by default can play an important role in reducing risk.
In a study published today, Comparitech researchers took a look at four of the most popular open-source CMSs (WordPress, Drupal, Joomla, and Ghost), to determine which has the strongest out-of-the-box security. The CMS platforms were assessed immediately following installation to determine their secure-by-default posture, with the assessment considering browser security controls, information disclosure, authentication securiy, and API and enumeration exposure.
Key findings include:
For full details, please see the research here: https://www.comparitech.com/news/which-cms-platforms-provide-the-strongest-out-of-the-box-security/
Share this:
Like this:
Related
This entry was posted on August 12, 2026 at 2:49 pm and is filed under Commentary with tags Comparitech. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.