Skip to content
Freehold CMSSelf-hosted PHP website software.
Downloads soon

Security belongs in ordinary operation.

Freehold CMS uses authenticated administration, capability checks, request validation, protected configuration practices and package inspection so important safeguards are part of normal work instead of an afterthought.

Controls inside the CMS

Administrative work requires an authenticated account and the appropriate capability. Requests are checked before data changes. Module packages are inspected before installation. Security & Checkup gives administrators one place to review important conditions.

Protection around the CMS

Use HTTPS, protect hosting and email accounts, limit administrator access, apply compatible releases and keep backups that can actually be restored. Outside providers need secure configuration as well.

A stronger routine

  • Unique administrator accounts.
  • Private configuration outside public storage.
  • Module readiness checks.
  • Backups before significant changes.
  • Testing for sign-in, forms and checkout.
  • Access removed when it is no longer needed.

Keep implementation detail where developers can use it.

The developer guide explains authorization, request checks, database access, uploads, secrets and provider callbacks without forcing buyers through a technical manual.

Review Free Core. Read Developer Security.