New Consortium Aims to Set PHP Security Standards

NEW YORK — A group of international PHP experts, including one of the founders of PHP enterprise platform developer Zend Technologies, have banded together and formed a new conglomerate aimed at promoting secure programming practices.

The newly formed PHP Security Consortium, created in response to the recent Santy worm outbreak that besieged phpBB bulletin boards across the Internet, intends to publish a variety of articles focused on security proofing PHP code and also audit commonly used PHP-coded applications

“PHP application security is a topic of growing important,” said Andi Gutmans, a charter member of PHPSC and one of the co-founders of Zend, a company that specializes in offering enterprise-ready PHP solutions.

“The launch of the PHP Security Consortium is a landmark even for the PHP community, and because most web development technologies face similar security concerns, we believe that developers using other solutions can also benefit from our efforts,” Gutmana said.

The group’s creation was spurred by a bevy of recent high-profile security flaws found in third-party applications, which the group says has hurt the credibility of PHP and the growing PHP scripting community.

Commonly used for allowing web pages to interact with MySQL databases, the 10-year-old open-source scripting language has experienced explosive growth recently, with companies like Yahoo, Lycos, Disney and Deutsche Lufthansa adopting its use for everything from simple web access to complex electronic ticketing systems.

“As PHP has transitioned from personal project to enterprise application development, the need to educate the community about secure programming practices has risen,” said PHPSC founder Chris Shiflett.

Shiflett, who is also the creator of PHPCommunity.org and sits on the Zend PHP Advisory Board, said that one of the biggest problems for the PHP community is the perception that the language is unsuitable for secure web use.

“There’s this odd tendency in the PHP community to call everything PHP, even if it’s just a third-party application written in PHP,” Shiflett said. “We saw this happen with the phpBB issue, even though it had nothing to do with a security problem in PHP.”

According to Shiflett, the new group will also be involved in experimental research in order to develop standards of best practice for PHP application development in addition to publishing documentation and tools to help prospective PHP programmers.

“Because PHP has a very low barrier to entry, a lot of inexperienced developers are using it for their solutions,” Shiflett told eWeek. “They don’t tend to understand Web application security and they’re creating application with serious vulnerabilities.

“There is this urgent need to educate these developers and provide them with resources to get up to speed,” Shiflett said.

Copyright © 2025 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

Hentaied Founder Romero 'Mr. Alien' on Fetish, Fantasy and Finding Order in Chaos

A sharp sting pierces the woman’s skin. Something foreign slips beneath the surface. Eggs, maybe. She doesn’t know it yet, but soon her body will become a vessel, a hive, a source of contamination.

AEBN Publishes Popular Searches for July, August

AEBN has published the top search terms for the months of July and August from its straight and gay theaters in all 50 states and the District of Columbia.

The Guardian Devotes Feature Article to XBIZ Amsterdam

British newspaper The Guardian sent a reporter to cover XBIZ Amsterdam earlier this month, resulting in a lengthy article about the annual European adult industry conference.

Pineapple Support Taps Char Borley as Brand Ambassador

Pineapple Support has named Char Borley as its newest brand ambassador.

Michigan Legislators Propose Online Porn Ban

Michigan lawmakers have introduced a bill that would make it illegal to distribute pornography via the internet in the state.

Florida AG Sues Aylo, Segpay Over State AV Law

Florida Attorney General James Uthmeier filed lawsuits against Aylo and Segpay on Monday with the 12th Judicial Circuit Court of Florida for noncompliance with HB3, the state's age verification law.

Colombian Court Sides with Performer Esperanza Goméz Over IG Suspensions

Colombia’s Constitutional Court last week ruled in favor of adult performer Esperanza Gómez in her legal battle against Meta over repeated suspensions of her Instagram account.

Missouri AG Announces Age Verification Rule to Take Effect Nov. 30

Newly appointed Missouri Attorney General Catherine Hanaway announced Friday that the state's recently approved age verification regulation for adult websites will go into effect on Nov. 30.

Aylo, Woodhull Freedom Foundation to Tackle Online Censorship in Virtual Seminar

Aylo and Woodhull Freedom Foundation will co-host a virtual panel addressing online censorship on Sept. 30.

Severe Sex Films Relaunches Site Through YourPaysitePartner

Severe Sex Films has relaunched its official website through YourPaysitePartner (YPP).

Show More