Security
As regards security of FreeMind, there are the following concerns:
- Data security
- General security other than data security
The first concern is covered in a dedicated article, Data security. The rest of this page deals with the second concern.
One item from Data security is relevant here: Since FreeMind 0.8.1, FreeMind uses a plugin architecture. In some software contexts, plugin architecture has been found to be a security concern. The latest releases without plugins are FreeMind 0.7.1 and FreeMind 0.7.1-XT. See also Plugin.
Groovy script security is a topic that is covered at Scripting#Security. Especially unrestricted scripts from untrusted sources are genereally dangerous. There is a related bug report applying to scripts possibly escaping the FreeMind script restrictions:
The restrictions are described at Scripting#Security.
A security issue on parsing of mind map XML was reported for Freeplane. The issue was assessed for Freemind:
- Freeplane security issue on parsing of mind map XML to be assessed for FreeMind, 2026, sourceforge.net
Conclusion: the issue does not apply to FreeMind 1.0.1. In brief, FreeMind uses NanoXML/Lite while Freeplane uses NanoXML/Java, a much more heavier/larger parser.