RoseaThemes
Product code and security updates
- Security of RoseaThemes product code
- Security fixes
- Bundled dependencies
- Vulnerability handling
- Product security documentation
- Security advisories
Keyboard shortcuts and in-page sections
RoseaThemes develops and maintains Moodle themes and plugins with security, responsible vulnerability handling, and long-term maintainability in mind. We maintain processes for vulnerability reporting, security updates, dependency monitoring, and Cyber Resilience Act compliance.
Security processes designed to support compliance with Regulation (EU) 2024/2847 — the Cyber Resilience Act.
Security is part of how RoseaThemes designs, reviews, and maintains commercial Moodle themes and plugins. We follow Moodle security APIs and development practices, review authentication and permission-sensitive functionality, check output escaping and user-controlled content, monitor bundled third-party dependencies, publish fixes when security issues are identified, and maintain a documented vulnerability handling process.
RoseaThemes products operate inside an existing Moodle environment. Security of Moodle Core, hosting infrastructure, server configuration, databases, authentication infrastructure, and third-party plugins remains outside the direct control of RoseaThemes.
If you believe you have found a security issue in a RoseaThemes product, please report it privately. Do not open a public support ticket or discuss the details in a public channel before we have had a reasonable opportunity to investigate and release a fix.
Security contact: security@rosea.io
Please include as much of the following as you can:
We encourage responsible disclosure and ask researchers not to publicly disclose vulnerabilities before RoseaThemes has had a reasonable opportunity to investigate and release a fix.
Reports are handled through a defined process. Serious or actively exploited vulnerabilities may also trigger reporting obligations under applicable EU legislation.
Published advisories describe confirmed issues in RoseaThemes products, affected versions, fixed versions, and recommended action. Severity labels: Critical, High, Medium, Low, Informational.
No active security advisories
No advisories match the current filters.
Security support covers investigation of reported vulnerabilities, security fixes, dependency-related fixes where applicable, and publication of security advisories. It is distinct from feature updates: a product may receive security support after feature development for that generation has slowed or ended.
| Product | Generation | Platform | Status | Security support | Support end | Latest version |
|---|---|---|---|---|---|---|
| Space 5 | 5.x | Moodle 5.1, 5.2 | Supported | Active | Announced with generation retirement | 5.0.5 |
| Alpha 5 | 5.x | Moodle 5.x | Supported | Active | Announced with generation retirement | Current |
| Universe 5 | 5.x | Moodle 5.x | Supported | Active | Announced with generation retirement | Current |
| Monocolor 5 | 5.x | Moodle 5.x | Supported | Active | Announced with generation retirement | Current |
| XY 5 | 5.x | Moodle 5.x | Supported | Active | Announced with generation retirement | 5.2.2 |
| BAZIS | 5.x | Moodle 5.1, 5.2, 5.x | Supported | Active | Announced with generation retirement | Current |
| Scholastica | 5.x | Moodle 5.x | Supported | Active | Announced with generation retirement | Current |
| Moon | IOMAD | IOMAD 5.1, 5.0, 4.5 | Supported | Active | Announced with generation retirement | 1.8.1.2 |
| RoseaThemes plugins | Current | Supported Moodle versions listed on the product page | Supported | Active | Announced with generation retirement | Current |
The EU Cyber Resilience Act introduces cybersecurity requirements for products with digital elements placed on the European Union market.
RoseaThemes maintains technical and organisational processes intended to support applicable CRA requirements for commercial Moodle themes and plugins. This page is a public overview of those processes. It is not a certification mark and does not claim that every product is already subject to a formal EU Declaration of Conformity.
Product-level practices used across RoseaThemes Moodle themes and plugins.
RoseaThemes maintains information about third-party components bundled with its products, including dependency name, version, component type, license, and security status where relevant.
We are preparing machine-readable SBOM support in formats such as CycloneDX and SPDX. The complete SBOM is not published on this page.
SBOM information may be provided to customers, auditors, or competent authorities where appropriate.
Customers receive updates through the RoseaThemes customer account, product changelogs, security advisories on this page, and critical customer notices where required.
Customers should keep both Moodle Core and RoseaThemes products within supported versions. RoseaThemes security updates do not replace Moodle Core security updates.
Security is considered from design through end of support.
Design
Security risks and permissions are considered when designing new functionality.
Development
Use Moodle APIs and established secure coding practices.
Review
Permission-sensitive and user-controlled flows are reviewed before release.
Testing
Review sensitive flows, dependencies, permissions, and user-controlled data.
Release
Versioned packages and changelog are published.
Monitoring
Reported vulnerabilities and dependency issues are reviewed.
Security updates
Security fixes are released for supported products.
End of support
When a generation is retired, the end of security support is announced in advance.
Open a product for supported versions, architecture notes, security support, advisories, and SBOM availability.
Modern Moodle theme for courses and dashboards. Platform: Moodle 5.1 and 5.2. Latest version: 5.0.5. Security support: active for the current generation.
Architecture: Moodle theme using core APIs for navigation, rendering, settings, and file handling. Bundled front-end assets are reviewed with the product. SBOM: available on request. Advisories: none active. End of support will be announced with generation retirement.
Flexible Moodle theme with branding options. Platform: Moodle 5.x. Security support: active for the current generation.
Architecture: Moodle theme using core permission, session, and output APIs. SBOM: available on request. Advisories: none active.
Feature-rich Moodle theme for larger platforms. Platform: Moodle 5.x. Security support: active for the current generation.
Architecture: Moodle theme using core APIs. SBOM: available on request. Advisories: none active.
Minimal Moodle theme with light and dark modes. Platform: Moodle 5.x. Security support: active for the current generation.
Architecture: Moodle theme using core APIs. SBOM: available on request. Advisories: none active.
Latest-generation Moodle theme with a front page builder. Platform: Moodle 5.x. Latest version: 5.2.2. Security support: active for the current generation.
Architecture: Moodle theme using core APIs. SBOM: available on request. Advisories: none active.
Academic-focused Moodle theme. Platform: Moodle 5.x. Security support: active for the current generation.
Architecture: Moodle theme using core APIs. SBOM: available on request. Advisories: none active.
Modern Moodle theme for education and training. Platform: Moodle 5.1, 5.2, and 5.x. Security support: active for the current generation.
Architecture: Moodle theme using core APIs. SBOM: available on request. Advisories: none active.
IOMAD multi-tenant theme. Platform: IOMAD 5.1, 5.0, and 4.5. Latest version: 1.8.1.2. Security support: active for the current generation.
Architecture: IOMAD theme using IOMAD and Moodle APIs for multi-tenant administration and learner UI. SBOM: available on request. Advisories: none active.
Includes Advanced Cookie & Consent Manager for Moodle. Supported Moodle versions are listed on the product page. Security support: active for the current generation.
Architecture: Moodle plugin using core APIs for settings, capabilities, and output. Cookie and consent features interact with site configuration; hosting, TLS, and Moodle Core remain customer responsibilities. SBOM: available on request. Advisories: none active.