New Consortium Aims to Set PHP Security Standards

NEW YORK — A group of international PHP experts, including one of the founders of PHP enterprise platform developer Zend Technologies, have banded together and formed a new conglomerate aimed at promoting secure programming practices.

The newly formed PHP Security Consortium, created in response to the recent Santy worm outbreak that besieged phpBB bulletin boards across the Internet, intends to publish a variety of articles focused on security proofing PHP code and also audit commonly used PHP-coded applications

“PHP application security is a topic of growing important,” said Andi Gutmans, a charter member of PHPSC and one of the co-founders of Zend, a company that specializes in offering enterprise-ready PHP solutions.

“The launch of the PHP Security Consortium is a landmark even for the PHP community, and because most web development technologies face similar security concerns, we believe that developers using other solutions can also benefit from our efforts,” Gutmana said.

The group’s creation was spurred by a bevy of recent high-profile security flaws found in third-party applications, which the group says has hurt the credibility of PHP and the growing PHP scripting community.

Commonly used for allowing web pages to interact with MySQL databases, the 10-year-old open-source scripting language has experienced explosive growth recently, with companies like Yahoo, Lycos, Disney and Deutsche Lufthansa adopting its use for everything from simple web access to complex electronic ticketing systems.

“As PHP has transitioned from personal project to enterprise application development, the need to educate the community about secure programming practices has risen,” said PHPSC founder Chris Shiflett.

Shiflett, who is also the creator of PHPCommunity.org and sits on the Zend PHP Advisory Board, said that one of the biggest problems for the PHP community is the perception that the language is unsuitable for secure web use.

“There’s this odd tendency in the PHP community to call everything PHP, even if it’s just a third-party application written in PHP,” Shiflett said. “We saw this happen with the phpBB issue, even though it had nothing to do with a security problem in PHP.”

According to Shiflett, the new group will also be involved in experimental research in order to develop standards of best practice for PHP application development in addition to publishing documentation and tools to help prospective PHP programmers.

“Because PHP has a very low barrier to entry, a lot of inexperienced developers are using it for their solutions,” Shiflett told eWeek. “They don’t tend to understand Web application security and they’re creating application with serious vulnerabilities.

“There is this urgent need to educate these developers and provide them with resources to get up to speed,” Shiflett said.

Copyright © 2026 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

AEBN Publishes Popular Searches by Country for April, May

AEBN has released the list of popular searches from its straight and gay theaters, by country, for April and May.

Ondato Joins Pineapple Support as Sponsor

Age and identity verification company Ondato has joined the ranks of over 70 adult businesses and organizations committing funds and resources to Pineapple Support.

2026 XBIZ Amsterdam Website Now Live, Registration Opens

XBIZ is pleased to announce that the website for its annual European conference, XBIZ Amsterdam, is now live.

MyMember.site Integrates FSC's 'PrivateAV' Age Verification Solution

MyMember.site has integrated Free Speech Coalition's PrivateAV age verification tool into its website-building platform.

Pearl Industry Network Opens Beta for Creator Networking App

Industry trade group Pearl Industry Network (PiN) has launched beta testing for the PiN Member App, a networking and collaboration tool for content creators.

FSC: W.V. Age Verification Law Takes Effect June 12

The Free Speech Coalition has issued a reminder notice that West Virginia's age verification law takes effect on June 12, 2026.

Pineapple Support Taps Brad Mitchell, Jean-Micheal Veen for Senior Leadership Positions

Pineapple Support has named Brad Mitchell as its new board president and Jean-Micheal Veen as technology and development chair.

Polish Government Proposes AV Mandate for Adult Sites

Poland’s Council of Ministers on Tuesday endorsed a proposed national law that would require sites and platforms to age-verify users to prevent minors from accessing adult content online.

Brazil Launches Complaints Page for AV Violations

Brazil’s National Data Protection Authority (ANPD) on Monday debuted a portal where citizens can report possible violations of the country’s Digital Statute for Children and Adolescents (Digital ECA), which requires adult websites to age-verify users located in Brazil.

FSC Launches 'Speak Out' Media Campaign for Creators

The Free Speech Coalition (FSC) has announced the launch of FSC Speak Out, a media campaign for content creators to tell their stories.

Show More