Is Concrete CMS Secure? What Businesses Should Know
Categories:
Just last week, a client asked us a simple but important question: “Is Concrete CMS secure?”
It’s a fair question. If your website represents your business, stores customer information, generates leads, or connects with other business systems, security shouldn’t be an afterthought.
The short answer is yes, Concrete CMS can be a very secure content management system when it is properly maintained, updated, and hosted in a secure environment.
And after more than two decades of developing and maintaining websites—including extensive experience with Concrete CMS—we’ve seen relatively few security incidents involving Concrete itself.
How Secure Is Concrete CMS?
Concrete CMS is an open-source content management system built with modern web-development practices and an established security process. Like WordPress, Drupal, Joomla, and other major CMS platforms, Concrete periodically receives security updates as vulnerabilities are discovered and software dependencies evolve.
That’s normal.
The more important question is how quickly vulnerabilities are addressed and whether website owners keep their installations current.
Concrete CMS publishes security advisories and releases security updates when issues are identified. Keeping the CMS core and extensions updated is one of the most important steps a website owner can take to reduce risk.
Our Experience With Hacked Concrete CMS Websites
Pixo has worked with Concrete CMS for many years, and one thing has consistently stood out: we are very rarely asked to clean up a hacked Concrete CMS website.
The U.S. Army uses the Concrete CMS, so it is held to a high standard in terms of security.
When we do encounter a compromised Concrete site, our investigation often points toward the hosting environment or server rather than an exploit of Concrete CMS itself.
A compromised hosting account, outdated server software, stolen FTP or control-panel credentials, insecure permissions, vulnerable third-party code, or another compromised website sharing the same server can all provide an attacker with access.
That distinction matters.
A website's security isn't determined solely by the CMS. It depends on the entire technology stack surrounding it.
What Makes a Concrete CMS Website Secure?
Think of website security as layers.
Concrete CMS is one layer. The web server is another. Hosting configuration, PHP, the database, SSL/TLS, administrator credentials, extensions, firewalls, backups, and access controls all contribute to the overall security posture of the website.
For a production Concrete CMS website, we generally recommend:
-
Keeping Concrete CMS on a currently supported and patched version
-
Applying security releases promptly
-
Keeping third-party packages and dependencies current
-
Using strong, unique administrator passwords
-
Restricting unnecessary administrator accounts and privileges
-
Enabling multi-factor authentication where appropriate
-
Maintaining secure server and file permissions
-
Keeping PHP and server software supported and patched
-
Using HTTPS throughout the site
-
Protecting hosting, SSH, SFTP, and control-panel credentials
-
Maintaining reliable off-site backups
-
Monitoring the server and website for suspicious activity
Even a well-secured CMS can be compromised if the server underneath it is vulnerable.
Is Concrete CMS More Secure Than WordPress?
This is one of the questions we hear from organizations evaluating content management systems.
There isn't a responsible answer that says one CMS is automatically secure and another is automatically insecure. Implementation, maintenance, extensions, hosting, credentials, and server configuration matter enormously.
There is, however, an important practical difference between the ecosystems.
WordPress powers an enormous portion of the web and has a vast ecosystem of themes and plugins from many different developers. That flexibility is one of WordPress's strengths, but every additional component can also expand the site's potential attack surface if it is poorly maintained or becomes vulnerable.
Concrete CMS has a smaller ecosystem and is often used for more deliberately engineered websites with fewer third-party components.
For organizations evaluating the two platforms, the better question isn't simply, “Which CMS is more secure?”
Ask instead:
Who is maintaining it, what third-party software is installed, how quickly are updates applied, and how secure is the environment hosting it?
Those factors can matter more than the CMS logo at the bottom of the technology stack.
Does Open Source Make Concrete CMS Less Secure?
No. Open-source software is not inherently less secure because its source code is publicly available.
In fact, open-source projects can benefit from developers and security researchers being able to inspect the code, identify vulnerabilities, and contribute fixes.
But open source doesn't eliminate responsibility.
Once a security update becomes available, organizations need a process for deploying it. Running an outdated version of any CMS—including Concrete—can unnecessarily expose a website to known vulnerabilities.
What About Concrete CMS Security Updates?
Concrete CMS maintains a security section where vulnerabilities and security-related releases can be documented.
For businesses running Concrete CMS, we recommend periodically reviewing the site's version and determining whether security or maintenance updates are available.
This is particularly important for older Concrete installations that may have been running reliably for years. A website can continue to work while its underlying CMS, PHP version, packages, or server components quietly become outdated.
Functional does not necessarily mean secure.
Hosting Security Matters More Than Many Businesses Realize
One of the biggest misconceptions about website security is that a hacked website automatically means the CMS was hacked.
That's not necessarily what happened.
Consider a server hosting multiple websites. If another application on that server is vulnerable—or if the hosting account itself is compromised—an attacker may be able to modify files belonging to the Concrete website without exploiting Concrete at all.
Similarly, compromised SSH, SFTP, FTP, hosting-panel, or administrator credentials can give an attacker legitimate access to systems that would otherwise be secure.
That's why investigating a compromised website requires more than scanning the CMS files. You need to determine how the attacker got in.
Simply deleting malicious files without closing the original attack vector often results in the site being compromised again.
Is Concrete CMS a Good Choice for Security-Conscious Organizations?
Concrete CMS can be an excellent option for organizations that want a flexible, professionally developed CMS without relying on a large collection of third-party plugins to provide fundamental functionality.
We've used Concrete CMS for business websites, custom applications, integrations, and organizations with complex content-management requirements.
Its security ultimately depends on the same principle that applies to virtually every modern web platform:
Good software still needs good maintenance.
A current Concrete installation on a properly configured server, with carefully selected extensions, strong credentials, appropriate access controls, regular backups, and ongoing monitoring provides a strong foundation for a secure website.
How Do I Know If My Concrete CMS Website Is Secure?
If your organization has been running Concrete for years, it's worth periodically conducting a security and maintenance review.
That review should go beyond simply checking the Concrete version. It should examine the CMS, installed packages, PHP version, server configuration, administrator accounts, file permissions, SSL configuration, backups, hosting environment, and any custom code or external integrations.
For older sites, it is also worth determining whether the current Concrete CMS version remains supported or whether an upgrade should be planned.
Need Help Securing or Updating a Concrete CMS Website?
Pixo has worked with Concrete CMS since its early years and has extensive experience developing, maintaining, upgrading, troubleshooting, and securing Concrete websites.
If you're concerned about the security of an existing Concrete CMS website—or you're considering Concrete for a new project—we can review the CMS and the surrounding hosting environment to identify vulnerabilities, outdated components, and opportunities to improve security.
Have a Concrete CMS security question? Contact Pixo and we'll take a look.
Share this Article
Need Website Design, AI for Business or SEO/AEO?
Take the first step in your business's success now by simply contacting Pixo and speaking with one of our design, development or SEO specialist today.
Categories
- Concrete5
- Awesome
- Denver Social Media
- Blog Consultation
- Website Development
- Website Design
- Search Engine Optimization
- Online Marketing
- Social Media
- multi-site
- ecommerce
- mommy blogging
- SEO/AEO
- Marketing
- Thankful
- Concrete5 CMS
- pumpkins
- Concrete5 Ecommerce
- Concrete5 Themes
- Pixo Jobs
- Social Media Marketing
- Concrete5 add-ons
- Concrete CMS
- Artificial Intelligence (AI)
- Website Security