Criticism of osCommerce stems from security vulnerabilities, including SQL injection via unchecked PHP code and loose file or directory permissions that are required for functionality.
On March 15 2009 osCommerce made the first official release of osCommerce Online Merchant V 3.0 as a stable, production ready alpha release.