Icy Phoenix Code Audit

Tags And Keywordscode audit


Goto page 1, 2  Next

Subject: Icy Phoenix Code Audit
Hi all,
I would like to keep you updated on some of the recent developments about Icy Phoenix.

Me and all developers are working on the whole package trying to improve some existing aspects but also implementing some new features.

Mainly we are focusing on performances and code optimization: trying to reduce the number of files and inclusions and creating classes for higher scalability and performances.

Regarding these aspects I would like you to know that I have decided to invest most part of donations received so far for a paid code audit by an external professional coder: this means that a specialized PHP coder will go through the code of the core files mainly trying to catch security holes and bugs, but also trying to improve the overall code by writing new code which helps with performance.

As you may imagine this kind of job is time consuming, and professional coders are not that cheap. This is why I'm also starting a new initiative here.

Starting from today, 90% of all the donations received until the end of February will be re-invested into code audit, while 10% will be donated to Haiti Cause.

Keep in mind that this project is open source, nobody has been charged for using it so far, and never will be. The amount you are willing to donate will be almost interely re-invested (apart of a small percentage that will go to charity) for improving the platform and your sites performances and security. I guess it is a great opportunity for us all to do something good for ourselves and the whole community.


How much should I donate?

Well that depends on how much you trust Open Source and how much your site is depending upon Icy Phoenix. Let me try to help you with some numbers / suggestions:

  • Icy Phoenix is open source, you have never been charged for using it, and you will never be.
  • Professional CMS platforms usually require a one time fee for the license plus an annual fee for supports and updates: on average pricing for the license is around 200 euros while about 100 euros are required for annual support fee (these amounts may also be really high for some kinds of products).
  • If your site is based upon Icy Phoenix, you have a good ratio of visits per day, and you are generating some revenues from your site, then you should really consider donating at least 30 euros to this initiative.
  • If you come regularly here (on this website) to get helped or styles or customization, and you think you found what you needed, maybe you should consider donating starting from 20 euros.
  • If your site is based upon Icy Phoenix, your community is quite big, but you are not generating income from your site, then a donation of 10 euros will be highly appreciated.
  • If your site is based upone Icy Phoenix, your site is amatorial and you don't mind about futures developments, well, then you don't need to donate unless you are feeling happy today! :wink:



Please keep in mind that I'm not forcing anyone to donate, feel free to donate or not, and please donate only if you trust this project and the open source world.


Also I would like to remind you that all donators who donate at least 10 euros will become part of a Special Group which have access to a special section where special content and informations are provided.


I will keep you updated about the total amount received and how those money will be used to improve Icy Phoenix.

Thank you for reading, and thank you in advance to all those who will donate.

Also a big thank you to all users that donated so far and allowed me to upgrade to a new server with higher performances.



Link to donation pages: Donations - Donate

Subject: Re: Icy Phoenix Code Audit
First :mricy: :mryellow: :mricy:

Please insert me in the Special Group :LOL:

It is a great idea to speed up things.
Thanks Luca

Profile PM  
Subject: Re: Icy Phoenix Code Audit
Second!! :mrorange:

VIP ... :oops: :P

Thanks for the info !!

Subject: Re: Icy Phoenix Code Audit
good idea Luca... :wink:

ps. TheSteffen ist der Förster :mricy:

Subject: Re: Icy Phoenix Code Audit
Thanks you Mighty Gorgon and all the team to make this proyect posible.

Subject: Re: Icy Phoenix Code Audit
Done! :mrgreen:

Great idea!



PS: Thank you for the hard work done so far!

Subject: Re: Icy Phoenix Code Audit
Wow :p

Profile PM  
Subject: Re: Icy Phoenix Code Audit
Thank you very much to all the donators, I hope I can make a little donation soon :)

Subject: Re: Icy Phoenix Code Audit
Thanks to all donators so far.

I have already agreed for a quote (for a basic audit) and the review will begin soon.

If the amount donated will rise I will ask for more things to check.

Thanks again.

Subject: Re: Icy Phoenix Code Audit
Hello!

I've done (Or I think so) a little donation. Could you check it? As Mozilla was getting some problems to connect with paypal... :oops:

Sorry for any apologize.!
:D

By the way, will you give instructions? And... will I be able to ask some questions without answer? :mrgreen:

Subject: Re: Icy Phoenix Code Audit
You can easily check that your donation has been stored here:
http://www.icyphoenix.com/donations.php

So... yes, your money have been received! Thanks.

Regarding questions, please use the appropriate forum section to ask what them! :wink:


_________________

The first part of the security audit has been completed, now we are discussing what needs to be fixed and what is the best way.

The good news is that Icy Phoenix core files doesn't suffer severe security issues.

The bad news is that there are some minor things to be fixed to improve security level which requires a lot of time (and many code changes).

I will publish a sort of report when the security audit is fully completed. I won't be very detailed because security is a very delicate matter (do not want to provide "free food" to malicious hackers), and maybe would be also better to release a patch or a new version before doing that. But I will decide later which is the best safe way to go.

Inactive User
Subject: Re: Icy Phoenix Code Audit
Mighty Gorgon wrote: [View Post]
Thanks to all donors so far.


I'll send you Euro's-x10 at the end of the month, just because I like you! :P

And because I may want to ask a couple of questions - If I don't sort it out before. :mryellow:

Now I'm being picky!

KasLimon has got it right - - - - - Donators

Donors give to charities, give blood and body bits etc. - Donators give money in support of something specific, as in what you are doing. :twisted:


Grrrrrrr! The English language! :censored:

Subject: Re: Icy Phoenix Code Audit
personal Ι like donation because I learn slowly slowly english with all of you here....... :mricy:

grrrrrrrrrrrrrr..... my English :google: translator..... :wallb:

Profile PM  
Subject: Re: Icy Phoenix Code Audit
Lopalong, I'm not sur that MG is really interested by your blood :mryellow: (I think it's better in hospital :p)

Profile PM  
Inactive User
Subject: Re: Icy Phoenix Code Audit
Whatever?

I decided to do the donation tonight until I ran into this!

Some information is incorrect or missing. Please correct your entries and try again.

# Address Line 1: Please enter a valid Address Line 1.
# Town/City: Please enter a valid Town/City.
# Postcode: Please enter a valid Postcode.
# Home Telephone: The telephone number is too short.
# Email Address: Please enter a valid address in the format .


Aside from the email address, I have no intention of providing any other information that can be used by "Telemarketers" through virtue of the fact that I would have entered into some sort of contractual arrangement with them simply by donating and providing any or all of my other personal details that they would now be free to use as they see fit.

Australia has laws against persistent telemarketers with it's "Do Not Call" register, and if for example I provided my phone number here - That protection would go down the drain.

Sorry MG - You get those requirements made OPTIONAL - And I'll donate to the cause.

Quite possibly, there are others who feel the same, but have not been vocal about the intrusion and unnecessary required information just to make a simple donation.

Goto page 1, 2  Next

Page 1 of 2


  
You cannot post new topics
You cannot reply to topics
You cannot edit your posts
You cannot delete your posts
You cannot vote in polls
You cannot attach files
You can download files
You cannot post calendar events

   

This is a "Lo-Fi" version of our main content. To view the full version with more information, formatting and images, please click here.

Powered by Icy Phoenix based on phpBB
Generation Time: 0.2149s (PHP: 18% SQL: 82%)
SQL queries: 17 - Debug Off - GZIP Enabled