Skip to Content
CMS Security Handbook: The Comprehensive Guide for WordPress®, Joomla!®, Drupal™, and Plone®
book

CMS Security Handbook: The Comprehensive Guide for WordPress®, Joomla!®, Drupal™, and Plone®

by Tom Canavan
April 2011
Intermediate to advanced
432 pages
11h 1m
English
Wiley
Content preview from CMS Security Handbook: The Comprehensive Guide for WordPress®, Joomla!®, Drupal™, and Plone®

CHAPTER 3

Preventing Problems Before They Start

You have a lot to discover and learn before you start building a site. Although this is not a design book, the initial design you choose can have a positive or negative effect on your security. One big way website owners get into trouble is not planning their sites ahead of time. Rather, they plan as they build, and that is not the best situation.

In fact, the general attitude for inexperienced website owners is summed up in the book, Joomla! Start to Finish: How to Plan, Execute and Maintain Your Web Site by Jen Kramer (Indianapolis: Wiley, 2010) in the title of Chapter 1: “I Want a Web Site and I Want it Blue — How Much Will That Cost?” Although this sounds like a parody, it's a situation that web developers face all the time.

One decision you'll make early on is what content management system (CMS) framework to choose. Each has its own unique approach to securing the CMS. Following are a few questions that you may want to research as they relate to your security profile:

  • Will you use SSL? (If you are supporting any kind of e-commerce, you will.)
  • Will you need a Virtual Private Server (VPS), or will shared hosting work?
  • What method of backup do you need, and will your CMS support it?
  • Have you verified that the third-party add-ons you have chosen are secure?
  • In the CMS of choice, do you understand the Access Control Lists (ACL) options? (This is important to control access to the site's resources.)
  • Does the CMS provide adequate ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.

Read now

Unlock full access

More than 5,000 organizations count on O’Reilly

AirBnbBlueOriginElectronic ArtsHomeDepotNasdaqRakutenTata Consultancy Services

QuotationMarkO’Reilly covers everything we've got, with content to help us build a world-class technology community, upgrade the capabilities and competencies of our teams, and improve overall team performance as well as their engagement.
Julian F.
Head of Cybersecurity
QuotationMarkI wanted to learn C and C++, but it didn't click for me until I picked up an O'Reilly book. When I went on the O’Reilly platform, I was astonished to find all the books there, plus live events and sandboxes so you could play around with the technology.
Addison B.
Field Engineer
QuotationMarkI’ve been on the O’Reilly platform for more than eight years. I use a couple of learning platforms, but I'm on O'Reilly more than anybody else. When you're there, you start learning. I'm never disappointed.
Amir M.
Data Platform Tech Lead
QuotationMarkI'm always learning. So when I got on to O'Reilly, I was like a kid in a candy store. There are playlists. There are answers. There's on-demand training. It's worth its weight in gold, in terms of what it allows me to do.
Mark W.
Embedded Software Engineer

You might also like

Preventing Web Attacks with Apache

Preventing Web Attacks with Apache

Ryan C. Barnett
What Successful Project Managers Do

What Successful Project Managers Do

W. Scott Cameron, Jeffrey S. Russell, Edward J. Hoffman, Alexander Laufer
How to Overcome a Power Deficit

How to Overcome a Power Deficit

Cyril Bouquet, Jean-Louis Barsoux

Publisher Resources

ISBN: 9780470916216Purchase book