It is difficult to make a definitive statement about the security of a particular CMS. However, it is a
fact that Craft CMS, due to its lesser popularity, is a significantly less
attractive target for attacks than, for example, WordPress.
Furthermore, Craft CMS is a relatively new system, meaning many of its core components are programmed
according to current developer standards. The technology stack and the system and database architecture
support the assertion that this system was built and is maintained by very experienced developers.
The circumstance of it being a commercial yet source-open system is also an indication of more
security. The code can be viewed at any time, and the team behind it is backed by a funding model that
makes the efforts for further development profitable. The same applies to the plugin directory. The
plugins listed here adhere to the quality standards defined in the documentation and are equally
chargeable. Consequently, it is also assured that plugin developers are remunerated for their valuable
work. Despite this, in the area of plugins, we as a web agency follow the approach of avoiding plugins
as much as possible if a feature can be realized with reasonable effort and in a user-friendly way
through core-side means. Our main concern is to keep dependencies low. This creates additional security
for your project based on Craft CMS.
Furthermore, the principle applies that up-to-date software is generally considered effective
protection against vulnerabilities and security gaps. Therefore, any software publicly deployed on the
web should be regularly and carefully maintained. Craft CMS fulfills this premise, as evidenced by the
very short intervals between software update releases. These consistently provide bug fixes, new
features, and changes, and, true to its reputation as a fundamentally secure system, barely any
security patches. The version history can be tracked
here. Feel free to contact us if you are interested in having your Craft
CMS website maintained.