A new version for Elgg 3.3 is now available in the download section.
Release notes for Elgg 3.3.11
Contributors
Bug Fixes
info@elgg.org
Security issues should be reported to security@elgg.org!
©2014 the Elgg Foundation
Elgg is a registered trademark of Thematic Networks.
Cover image by Raül Utrera is used under Creative Commons license.
Icons by Flaticon and FontAwesome.
Hello,
I was wondering what is the best security settings for the Elgg 3.3.8, as far of the accepting new users that register themselves.
My site's settings are:
Users:
New users require manual validation by an administrator ( No)
Allow user default access (Yes)
The settings on the control panel, and if you think that it is dangerous because of spammers and others, or if there is a stopper plugin or not.
I had it where I was approving, but then people try and never came back to fill up the profile.
Another thing is that I want to upgrade but, i'm worry about my plugins won't work with the higher Elgg versions.
What could be your suggestion about the security of the site? Any ideas. Bookoflikes
@Book of Likes,
I would recommend you enable the plugin User validation by Email. this will make at least sure the users have a valid (working) e-mail address. There are other spam helper plugins here on the community which you could have a look at.
Updating Elgg with patches (so from 3.3.8 to 3.3.11) will always work without problems.
Minor updates (from 3.3 to 3.4) should work but require a tiny bit of testing.
Major updates (from 3.x to 4.x) will break everything and require extensive testing.