Background
The Drupal "Overview for Consultants" page ( http://drupal.org/node/43438 ) in the handbook needs information on Security. I'd like to collect that in this forum thread and then add it into the Handbook. I've started some research, but would appreciate any other input people have.
I have frequently turned to Secunia reports to compare the history and security of a product. They have information on more than 6,500 different products at http://secunia.com/product/
Drupal's Review
Drupal 4.x is reviewed here: http://secunia.com/product/342/
They provide
"Statistics Based on Advisories
- Advisories Month by Month
- Solution Status
- Criticality
- Where
- Impact"
They do not provide the amount of time between the different milestones in the process (e.g. time from vulnerability known to developers to vulnerability patch, and the point -if any- where an exploit was created).
Drupal has been relatively secure, especially considering that (in my knowledge) the time between knowledge of the vulnerability and patch-release is very small if not immediate.
Other Systems
Of course, when presenting Security information it is important to consider "secure compared to other products that do the same thing" and in these cases, there are some systems which have better records than Drupal, but most do not. I would like to create a comparison chart, but was curious which of these systems seems best to compare Drupal. When considering alternatives to Drupal for different purposes, which of these systems do you think are most often included in the list?