This module is inherently insecure, as it requires that the webserver process has write access to the PHP code that powers the site. This means that nearly *any* vulnerability could be elevated into a remote code execution hole. :(
The safe way to do automatic site updates is via the approach spelled out at http://drupal.org/node/124661 and http://drupal.org/node/192651. The 5.x-1.0-rc1 release of http://drupal.org/project/drush includes an implementation of this automated update script.
Therefore, the security team would like to kindly request that the author of this module abandon development and let us unpublish the project node and send out a security announcement that users are strongly encouraged to a) uninstall the module and b) restore the filesystem permissions on their drupal sites to something that's not inherently insecure as required by this module.
Thanks,
-Derek (for the Drupal Security Team)
Comments
Comment #1
drawk commentedAbsolutely, feel free to unpublish this module. As you said, there are now better and more secure alternatives.