New Consortium Aims to Set PHP Security Standards

NEW YORK — A group of international PHP experts, including one of the founders of PHP enterprise platform developer Zend Technologies, have banded together and formed a new conglomerate aimed at promoting secure programming practices.

The newly formed PHP Security Consortium, created in response to the recent Santy worm outbreak that besieged phpBB bulletin boards across the Internet, intends to publish a variety of articles focused on security proofing PHP code and also audit commonly used PHP-coded applications

“PHP application security is a topic of growing important,” said Andi Gutmans, a charter member of PHPSC and one of the co-founders of Zend, a company that specializes in offering enterprise-ready PHP solutions.

“The launch of the PHP Security Consortium is a landmark even for the PHP community, and because most web development technologies face similar security concerns, we believe that developers using other solutions can also benefit from our efforts,” Gutmana said.

The group’s creation was spurred by a bevy of recent high-profile security flaws found in third-party applications, which the group says has hurt the credibility of PHP and the growing PHP scripting community.

Commonly used for allowing web pages to interact with MySQL databases, the 10-year-old open-source scripting language has experienced explosive growth recently, with companies like Yahoo, Lycos, Disney and Deutsche Lufthansa adopting its use for everything from simple web access to complex electronic ticketing systems.

“As PHP has transitioned from personal project to enterprise application development, the need to educate the community about secure programming practices has risen,” said PHPSC founder Chris Shiflett.

Shiflett, who is also the creator of PHPCommunity.org and sits on the Zend PHP Advisory Board, said that one of the biggest problems for the PHP community is the perception that the language is unsuitable for secure web use.

“There’s this odd tendency in the PHP community to call everything PHP, even if it’s just a third-party application written in PHP,” Shiflett said. “We saw this happen with the phpBB issue, even though it had nothing to do with a security problem in PHP.”

According to Shiflett, the new group will also be involved in experimental research in order to develop standards of best practice for PHP application development in addition to publishing documentation and tools to help prospective PHP programmers.

“Because PHP has a very low barrier to entry, a lot of inexperienced developers are using it for their solutions,” Shiflett told eWeek. “They don’t tend to understand Web application security and they’re creating application with serious vulnerabilities.

“There is this urgent need to educate these developers and provide them with resources to get up to speed,” Shiflett said.

Copyright © 2026 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

Pineapple Support Partners with Better Life Science's 'STD Hero'

Pineapple Support has partnered with Better Life Science brand STD Hero.

Brazil Sets Enforcement Timeline for New AV Rules

Brazil’s National Data Protection Authority (ANPD) on Friday published a timeline outlining planned steps for monitoring and enforcing age verification under the country’s Digital Statute for Children and Adolescents (Digital ECA), which took effect Tuesday.

Utah Governor Signs 'Porn Tax' and VPN Rule Into Law

Governor Spencer Cox on Friday signed into law a bill to tax adult websites and make them liable if minors circumvent geolocation.

BranditScan Launches 'White Glove' Subscription Tier

BranditScan has launched its new White Glove subscription tier for creators.

German Court: Regulator Can't Block Creator's IG Account, Only Posts

A German court has ruled that while a regional media regulatory agency may block specific Instagram posts that include material deemed harmful to minors, it cannot ban an entire Instagram account due to such a post.

Brazil Lays Out Preliminary Guidelines for New AV Requirements

President Luiz Inácio Lula da Silva on Wednesday signed a decree establishing guidelines for new regulations requiring adult websites to age-verify users located in Brazil.

Senate Committee Debates Section 230 Reform

The U.S. Senate Committee on Commerce, Science, and Transportation held a hearing Wednesday on potential changes to Section 230 of the Communications Decency Act, which protects interactive computer services — including adult platforms — from liability for user-generated content.

Pearl Industry Network Offers Free Creator Memberships

Industry trade group Pearl Industry Network (PiN) has launched its free creator membership initiative.

Sam Bird Acquires Fanblast

Sam Bird, former co-director of global talent agency Surge, has acquired creator monetization tool Fanblast and named himself CEO.

'SheHerGirls' Launches Through Paysite.com

The braintrust behind PoleVixens has officially launched a new membership site, SheHerGirls, also through Paysite.com.

Show More