ciciFTP

Security

ciciFTP carries your server passwords, and it was written with that in mind. Security is the default behaviour, not a setting. Everything below is on out of the box.

Your secrets

Server identity

No trust in server data

Release integrity

Automation surface

The scripting language is a whitelist: no shell commands, no eval, no process launching — a shared script cannot execute code.

Audits

Three separate review rounds were done before release (attack-surface map, attack simulations against real servers, dependency scan); every finding was fixed and added to the automated tests (27 suites, 895 checks, run against real FTP/SFTP/WebDAV/S3/Azure servers).

Reporting a vulnerability

If you believe you found a security issue, please write to us first: security@kodhisar.com (/.well-known/security.txt). We answer within 72 hours and ask you to keep details private until a fix is released.