I just upgraded to 1.4.1 and cleared the security test (cf topic 72502), but in the server weblog the paths are not the same as my paths. My url is of the type www.example.com/~username/geeklog (i.e. I have ~/public_html/geeklog as document root), but the paths in the weblog are of the type www.example.com/~username (/config.php, /logs/error.log, /plugins/staticpages/functions.inc, /system/lib-security.php, /backups/test.txt, /data/test.txt), so the right files were actually never checked. It seems as if the function urlToCheck in sectest.php cuts off the geeklog part somewhere. (My geeklog root is ~/www/geeklog.)