Piwik 1.1 closes critical security holes
Summary
In January 2011 the free web analytics software Piwik appeared in version 1.1 with security holes closed. As a precaution, the developers had commissioned Stefan Esser’s company SektionEins with a five-day review of the source code. Its hardening advice was incorporated into the new version.
Ideas
- A project had its code reviewed before attackers found holes.
- Besides bugs, an external audit also provides advice on architecture.
- Five days of review were enough to uncover several holes.
Insights
- Proactive audits are particularly valuable for self-hosted web applications.
- Privacy-friendly analytics must also be technically secure.
Facts
- SektionEins was founded by the security expert Stefan Esser.
- The review lasted five days.
- Piwik emerged from the phpMyVisites project and is licensed under the GPL.
References
Critique
- The report names neither the type nor the severity of the holes found.
Remarks
- Piwik has been called Matomo since 2018.
Recommendations
- Always keep self-hosted web analytics such as Matomo up to date.
- Plan regular external security reviews for your own web applications.
Links to the original source and the Web Archive open in a new tab.