5 years of Securing Laravel!
Yikes! I've been writing Securing Laravel for 5 years! 😲
Greetings, my friends!
Somehow August is almost over (no idea how that happened, didn't we just have May???), which means I've been writing Securing Laravel for 5 years!
31st August 2026 marks 5 years since my first post, and a lot has changed since then - both in the industry, and for me personally. So, as is my tradition, I want to take some time to reflect on the past 12 months of Securing Laravel.
I first launched Laravel Security in Depth (as it was known back then) on 31st August 2021, at the time I was taking a break from working as a developer due to burnout, speaking at Laracon Online during COVID, and wanted a new outlet for sharing my security experience with the Laravel community. The name changed to Securing Laravel, the site moved from Substack to Ghost, but I kept posting monthly In Depth articles and weekly Security Tips... well, I did until October last year - but we'll get to that.
Before we dive into the details, looking at both what was published and what was going on behind the scenes, I want to thank each and every one of you. Security isn't a shiny trendy topic that gathers huge momentum off flashy announcements, it's a slow burn, something you need to care about and take time away from other priorities to learn about and explore. So I appreciate everyone who takes the time to read my articles, who cares about writing secure code, and learning more about security. I've received some really encouraging and heartfelt messages of support from many of you over the years, and I thank you all for that. I could not do this without your support.
Also, I need to give a very special thanks to my premium subscribers who've stuck with me during the last 12 months, despite pauses and delays with the In Depth articles they pay for! Your trust and support means the world, and I'm lucky to have you.
Let's look at the past year and what was published...
Published Articles
For these numbers to make sense, we need to take into account that I took all of October through to January off, restarting articles on the 4th February 2026. That's four months without any articles. (I issued credit to everyone's accounts during this time to make up for the missed articles.)
After that, I got back into the schedule until the middle of March, when it all fell apart again. I've been posting infrequently since then, but getting more frequent each month.
With that in mind, here are the raw numbers:
The In Depth articles covered Email Verification (it's not as simple as you think), Public Livewire Properties (soo much fun during security audits!), Version Number hijacking, a fun vulnerability with an API, SameSite=None, and CSRF, and a deep dive into unserialise() and how to abuse it.
While the Security Tips looked at XSS through Alpine directives, bypassing CSPs, broadcast channels, JWTs, GET request abuse, a Signed URL trap, safely updating packages, Slopsquatting, and SameSite cookies.
Definitely not as many as previous years, but I'm proud of each of these articles and have had some great feedback. It was nice to get back into technical dives with the latest In Depth on unserialize(), and Slopsquatting definitely made an impact talking about a new vector many folks hadn't even considered.
What about AI?
Given how much is happening in the world right now with AI, so much of our industry is changing, and the question is: why haven't I written about AI?
The answer is simple: I haven't felt confident doing so.
I write all of my articles by hand, none of it is AI generated (not-so-humble-brag?), and I need to be confident with what I'm writing and researching before I'll write the article. This slows me down and can limit what I cover, but I would rather limit my scope than put out badly researched articles and give you the wrong information.
It would be easy to add AI into my workflow to help me write articles faster, to keep up with my schedule, however that's not something I feel comfortable doing. These articles are my voice, thoughts, experience, recommendations, and bad jokes. AI cannot replicate that, and I would rather miss deadlines and send out articles late than compromise their quality.
That said, I need to spend some time learning AI Security properly, trying different models and methods, and then write articles about it. To be fair, I do use AI as part of my security audit work, however I'm using it from a pentesting/code auditing approach, and have a number of internal tools and scripts that enhance the results. All of this is valuable, but not easily sharable or relatable for developers, so I need to reconcile that information with something suitable for a wider audience.
Subscribers
Last year I reported 4,017 subscribers (both free and paid), and this year that's only slightly higher at 4,070 subscribers.

That's a discouraging number.
I expected the growth to be lower, given my activity, however that's not much. That said, the growth for last year (2025) was only 159 - compared with 1,337 for 2024. So this is probably an indicator of a bigger change.
Paid subscribers went from 183 to 142, which I did expect, given my inactivity and delays with posting. However, it does hurt financially, and means Securing Laravel is no longer paying for the time I spend on it, like it once was.
I expected to lose paid subscribers due to my inactivity, however this trend of lower subscribers (both free and paid) has been going on for longer than this year. The industry is changing so much at the moment, AI has replaced so much of our learning, and I believe text-based articles and paid articles are a much harder sell.
A question I often ask myself is: when you can ask your AI to teach you something - or just do it for you - why would you read my articles and sign up for my emails?
Analytics
Next up, Analytics from Fathom:

The previous period comparison paints a pretty clear picture. There were multiple factors working against me here, but not all of them within my control. All I can do is keep persisting and see where we end up.
In terms of top pages, the Livewire RCE is still top of the list, followed by the popular Pentesting part 1 article, and then the APIs responding to HTTP.

The Top 10 countries is missing Australia 😮, Germany has overtaken the Netherlands, and China has appeared from nowhere!
The Past Year...
I wrote last year about having a "couple of brutal years personally", and this year was no different - in fact, it was worse. I alluded to a bunch of stuff that was going on, and so many of them hit hard in the last 12 months.
I was diagnosed with Rheumatoid Arthritis (RA) many years ago and had been successfully managing it via a vegan diet for years, but a couple of years ago it started to get really bad, so bad that I was unable to use my right wrist and knee without immense pain. I went to a new rheumatologist and she diagnosed me with Psoriatic Arthritis (PsA) (the original RA was wrong), and started me on the medication for that.
That medication stopped working this year, bringing on even more chronic pain, so now I'm in the "fun" process of testing different drugs to find one that allows me to use my wrist without too much pain. This makes working (especially typing!) difficult some days, and despite trialling multiple fancy keyboards, I still haven't found a good solution for when it gets bad.
Alongside this, my ex-wife and I separated near the end of last year, after 16 years of marriage with 2 kids. So when I took time off from October, I was rebuilding my life, figuring out what I was going to do, and finding a new place to live. There is still so much to do, and is by far the hardest thing I've ever been through.
The separation combined with chronic pain destroyed my mental health, and my physical health went downhill too. I am incredibly grateful that I was already seeing a psychologist before all of this happened, and am still able to see him every fortnight to work through what's going on in my life. I don't think I would be doing anywhere near as well if I didn't have his support. I also have a special group chat with close friends who have done more for me than they realise.
Life is a massive juggling act right now, and I am so incredibly grateful for my clients who are understanding when I need to shift dates to accommodate my health. Securing Laravel unfortunately comes in second to my client work, and most of my delays are due to me simply not having enough usable work time in the day to write an article.
One thing that has really helped me this year has been getting into Pottery - every Sunday night for 3 hours. It's the highlight of my week, when I get to ignore technology and throw all of my concentration into working with clay on the wheel, using my hands to feel connected and present.
You can find my work over at: https://pottery.valorin.net/.






Some of my recent pieces
Looking Ahead
For now, I am just working on improving my posting schedule. I am tracking the In Depth articles that are overdue and will keep publishing them until I've caught up - there are currently 2 overdue.
I don't have the headspace for anything bigger until I catch up and get back to my schedule, although I do need to figure out where this is all going and if I need to pivot in a different direction.
AI is definitely an area I need to start writing, it's too big and too well used to ignore.
A quick question on value:
Paid subscriptions have dropped this year, and I believe it's not just because of my inactivity. It might just be the cost, but rather than asking "Is Securing Laravel too expensive?", maybe a better question is:
What would make a premium subscription genuinely worth it to you? More frequent In Depth articles? Different topics (i.e. AI security, etc)? Something I'm not offering yet?
If price genuinely is the blocker for you, tell me that too!
Thank you.
Once again, thank you for being here. If you've made it this far, you obviously care about what I have to say, and that means so much to me.
Thank you. 🥰
As I've done in previous years, can I please ask you to do two things:
- Leave a comment or send me an email, answering:
- What you love about Securing Laravel.
- What you think can be improved about Securing Laravel.
- Please share a recent article with at least one person.
Maybe forward an email to a colleague with a useful security tip that might be relevant to them, or post it up on your social media of choice?
Thank you,
Stephen