Note: You are currently viewing documentation for Moodle 3.7. Up-to-date documentation for the latest stable version of Moodle may be available here: Vendor directory security check.

Vendor directory security check

From MoodleDocs
Revision as of 07:31, 7 September 2017 by David Mudrak (talk | contribs) (Initial version of the page, with the info simply copied from Moodle)
(diff) ← Older revision | Latest revision (diff) | Newer revision → (diff)

Vendor directory security check

The vendor directory should not be present on public sites.

The vendor directory inside the Moodle dirroot contains various third-party libraries and their dependencies, typically installed by the PHP Composer. It may be needed for local development, such as for installing the PHPUnit framework. But it can also contain potentially dangerous code exposing your site to remote attacks.

It is strongly recommended to remove the directory if the site is available via a public URL, or at least prohibit web access to it.