While I was browsing my Twitter timeline today, I saw a tweet by VUPEN security about a possible compromise of PHP.net server(s) and a potential PHP source backdoor.

We are aware of a possible compromise of PHP.NET server(s) and a potential PHP source backdoor. “wiki.php.net” was taken offline

–VUPEN Security

Before I continue, I want to make clear that I don’t have any information regarding the compromise, neither can I state that PHP source code was or wasn’t backdoored, since I have not inspected the code, neither have I reviewed the revision log and the changes committed to PHP source tree. This information is publicly available at http://svn.php.net.