New Consortium Aims to Set PHP Security Standards

NEW YORK — A group of international PHP experts, including one of the founders of PHP enterprise platform developer Zend Technologies, have banded together and formed a new conglomerate aimed at promoting secure programming practices.

The newly formed PHP Security Consortium, created in response to the recent Santy worm outbreak that besieged phpBB bulletin boards across the Internet, intends to publish a variety of articles focused on security proofing PHP code and also audit commonly used PHP-coded applications

“PHP application security is a topic of growing important,” said Andi Gutmans, a charter member of PHPSC and one of the co-founders of Zend, a company that specializes in offering enterprise-ready PHP solutions.

“The launch of the PHP Security Consortium is a landmark even for the PHP community, and because most web development technologies face similar security concerns, we believe that developers using other solutions can also benefit from our efforts,” Gutmana said.

The group’s creation was spurred by a bevy of recent high-profile security flaws found in third-party applications, which the group says has hurt the credibility of PHP and the growing PHP scripting community.

Commonly used for allowing web pages to interact with MySQL databases, the 10-year-old open-source scripting language has experienced explosive growth recently, with companies like Yahoo, Lycos, Disney and Deutsche Lufthansa adopting its use for everything from simple web access to complex electronic ticketing systems.

“As PHP has transitioned from personal project to enterprise application development, the need to educate the community about secure programming practices has risen,” said PHPSC founder Chris Shiflett.

Shiflett, who is also the creator of PHPCommunity.org and sits on the Zend PHP Advisory Board, said that one of the biggest problems for the PHP community is the perception that the language is unsuitable for secure web use.

“There’s this odd tendency in the PHP community to call everything PHP, even if it’s just a third-party application written in PHP,” Shiflett said. “We saw this happen with the phpBB issue, even though it had nothing to do with a security problem in PHP.”

According to Shiflett, the new group will also be involved in experimental research in order to develop standards of best practice for PHP application development in addition to publishing documentation and tools to help prospective PHP programmers.

“Because PHP has a very low barrier to entry, a lot of inexperienced developers are using it for their solutions,” Shiflett told eWeek. “They don’t tend to understand Web application security and they’re creating application with serious vulnerabilities.

“There is this urgent need to educate these developers and provide them with resources to get up to speed,” Shiflett said.

Copyright © 2026 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

Pearl Industry Network Launches 'TrustLink' Verification Platform for Creators

Trade group Pearl Industry Network (PiN) has launched TrustLink, its free verification platform for creators.

FSC Updates Complaint in Tennessee AV Case, AG Motions to Dismiss

The Free Speech Coalition this week filed an amended complaint in its lawsuit challenging the Protect Tennessee Minors Act as unconstitutional, in response to which the Tennessee attorney general motioned for dismissal of the case.

Cherie DeVille Joins Woodhull Freedom Foundation 'Free Speech' Panel

Multi-XMAs winner Cherie DeVille will join the upcoming Woodhull Freedom Foundation panel series "Fact Checked by Woodhull," addressing free speech on Feb. 26.

Wisconsin AV Bill Moves Ahead, Minus Anti-VPN Provisions

The Wisconsin state Senate on Wednesday advanced a bill that would require adult websites to verify the ages of users, but approved an amendment striking proposed language that would have required sites to block virtual private network traffic.

Pineapple Support Introduces 'Wellbeing by PS' Service

Pineapple Support has debuted its new Wellbeing by PS service, providing mental health support packages for companies and agencies.

MyMember.site Integrates Bluesky Functionality

MyMember.site has added Bluesky features to its website management platform.

GirlsDoPorn Defendants Ordered to Pay Victims $75.5 Million

A federal court has ordered former GirlsDoPorn owner Michael Pratt and his co-defendants in the GDP sex trafficking case to pay restitution totaling $75,568,283.47 to 106 victims.

SWR Data Publishes 'Clip Trend' Report

Adult industry market research firm SWR Data has published a report on clip platform performance and sales.

Another German Court Rejects Blocking Orders Against Pornhub, YouPorn

A German court has blocked the Rhineland-Palatinate Media Authority (MA RLP) from forcing telecom providers based within the court’s jurisdiction to cut off access to Aylo-owned adult sites Pornhub and YouPorn.

Ofcom Fines Kick Online Entertainment $1 Million for AV Noncompliance

U.K. media regulator Ofcom on Thursday fined Kick Online Entertainment 800,000 pounds (more than $1 million) for failing to implement age checks as required for compliance with the Online Safety Act.

Show More