SaaS Ranking

security.txt (RFC 9116) in Content management systems

It tells a researcher where to report a vulnerability instead of guessing.

3 of 16 vendors we measured here publish it, that is 19%. Last checked 2026-09-03.

19% here against 13% across every category we measure. Content management systems sits above the overall share for this criterion.

Back to security.txt (RFC 9116) across all categories, or to Content management systems.

Published

Served at /.well-known/security.txt.

VendorWhat we found
Craft CMS https://craftcms.com/.well-known/security.txt
DatoCMS https://www.datocms.com/.well-known/security.txt
Ibexa https://ibexa.co/.well-known/security.txt

No security.txt found.

We reached at least one address for each of these vendors and none of them carried it. That is what we found at the addresses we checked, on the date we checked them, and not a statement about what the vendor has.

VendorWhat we found
ButterCMS 1 address checked
Cockpit 1 address checked
Concrete CMS 1 address checked
Contentstack 1 address checked
CoreMedia 1 address checked
Decap CMS 1 address checked
Directus 1 address checked
Drupal 1 address checked
FirstSpirit 1 address checked
Keystone 1 address checked
Progress Sitefinity 1 address checked
TYPO3 1 address checked
Uniform 1 address checked

Not measured

We could not look at these, or their robots.txt asks us not to. That says something about our measurement, not about them, and they are left out of the percentage above.

VendorWhat we found
Builder.io The vendor’s server blocked or rate-limited our crawler, so this was not measured.
Contentful The vendor’s server blocked or rate-limited our crawler, so this was not measured.
Grav The vendor’s server blocked or rate-limited our crawler, so this was not measured.
Silverstripe The vendor’s server blocked or rate-limited our crawler, so this was not measured.
Squiz The vendor’s server blocked or rate-limited our crawler, so this was not measured.

Found something we missed? Tell us and the next run picks it up.