Login / Status
developer.Resource
Home . Teams . Security . Extension Security Policy
Sponsors
hosted by punkt.deTYPO3 and Open Source MagazineAOE Media

TYPO3 Extension Security Policy version 1.0

This is the official policy on the handling of security incidents, as defined by the TYPO3 Security Team. When this text says "we", "our" or "us", we mean the TYPO3 Security Team.

This policy is subject to change over time, so please make sure to have the latest version whenever you use it. The latest version of this document can be found on http://typo3.org/teams/security/extension-security-policy/

For users downloading a TYPO3 extension: Extension users

When downloading an extension from the public TYPO3 Extension Repository, you should be aware of the following points in regards to security.

For users creating a TYPO3 extension: Extension developers

When creating an extension, we expect you to follow the TYPO3 Coding Guidelines2, to read the TYPO3 Security Cookbook3, and do your upmost to make the extension secure. If you are unsure if a part of your extension is insecure, feel free to email us at security@we dont want spamtypo3.org with your question and extension code, so we can help you.

In case you become aware of a security issue inside your (already published) extension, you are required to inform us about it. The work-flow below applies accordingly. Do not mention the issue to others, and do not upload a fixed version without coordinating with us.

In case we are notified by a third party, or find a security issue in your extension ourselves, the following work-flow will occur:

The following situations will, without exception, require a full third party review of your extension:

For users reporting a security issue: Issue reporters

We highly appreciate your security awareness.

In order to provide maximum security for all TYPO3 users, we kindly request you to act responsible by following these guidelines: