Application controls reviewed
- Parameterized PDO queries and native prepared statements.
- POST CSRF checks, output escaping and rich-text filtering.
- Role, publisher/journal scope, manuscript and file-access checks.
- Password hashing, session ID rotation, secure-cookie settings and sign-in throttling.
- Upload extension/MIME allowlists, randomized filenames and protected storage.
- Two-factor failed-code throttling and active-account validation added in 2.4.
- Installer CSRF, configuration/lock protection and generic production error responses added in 2.4.
Production configuration
Use HTTPS everywhere, keep debug false, enable two-factor authentication for administrators, and protect database, SMTP and cPanel credentials. Preserve the application encryption secret during upgrades; replacing it can make stored encrypted credentials unreadable. Restrict installer access before first setup and remove installation/migration entry points afterwards.
Uploads and retention
File type checks do not provide antivirus scanning. If required by institutional policy, add scanning at the hosting/service layer. Back up files and database together. Do not remove audit history, memberships, manuscripts or schema objects as routine cleanup.
Security review limits
This release includes a focused source review and targeted hardening, not an independent penetration test or a guarantee against every attack. Live hosting configuration, external integrations, delivery, data-dependent permissions and business workflows require staging verification. Read the bundled VALIDATION.md for checks actually performed and remaining limits.