Which CMS platforms provide the strongest out-of-the-box security? 

Content Management Systems (CMSs) power millions of websites worldwide, making them one of the most common ways to publish content online. Because many CMS users have limited cybersecurity expertise, the security protections enabled by default can play an important role in reducing risk.

In a study published today, Comparitech researchers took a look at four of the most popular open-source CMSs (WordPress, Drupal, Joomla, and Ghost), to determine which has the strongest out-of-the-box security. The CMS platforms were assessed immediately following installation to determine their secure-by-default posture, with the assessment considering browser security controls, information disclosure, authentication securiy, and API and enumeration exposure. 

Key findings include: 

  • WordPress had the weakest out-of-the-box security protections, with a score of 8 out of 100
  • Drupal achieved the highest overall score (27.1 out of 100) – note that none of the tested CMSs provided a particularly strong security posture immediately after installation
  • Joomla has had the greatest number of disclosed vulnerabilities in the past five years
  • Drupal recorded the highest number of high- and critical-severity core vulnerabilities between 2021 and 2025
  • WordPress has the largest extension ecosystem, which may increase exposure to security risks associated with third-party plugins

For full details, please see the research here: https://www.comparitech.com/news/which-cms-platforms-provide-the-strongest-out-of-the-box-security/

Leave a Reply

Discover more from The IT Nerd

Subscribe now to keep reading and get access to the full archive.

Continue reading