Securing Laravel
  • Home
  • In Depth Articles
  • Security Tips
  • Archives
  • About
  • Laravel Security Audits & Pentests
  • Practical Laravel Security Course
Sign in Subscribe
Newsletter

Don't miss the Laracon Online Discount!

Subscribe now to get 25% off your Laravel Security In Depth subscription!

Stephen Rees-Carter

Stephen Rees-Carter

28 Sep 2022 — 1 min read
Share
Don't miss the Laracon Online Discount!

This post is for subscribers only

Subscribe now

Already have an account? Sign in

Read more

5 years of Securing Laravel!

5 years of Securing Laravel!

Yikes! I've been writing Securing Laravel for 5 years! 😲

By Stephen Rees-Carter 31 Aug 2026
Security Tip: Help Password Managers Get It Right!

Security Tip: Help Password Managers Get It Right!

[Tip #134] Laravel's password helper has a great little feature you may have missed: it can generate browser-friendly password rules automatically! 🤓

By Stephen Rees-Carter 29 Aug 2026
In Depth: From Serialised String to RCE!

In Depth: From Serialised String to RCE!

[In Depth #42] unserialize() looks harmless - it just rebuilds your data - but feed it the wrong string and it'll rebuild an attacker's object, quietly turning Laravel's own code into remote code execution. Let's pull a real RCE apart. 😈

lock-1 By Stephen Rees-Carter 21 Aug 2026
Security Tip: Do You Know Your SameSite Cookies?

Security Tip: Do You Know Your SameSite Cookies?

[Tip #133] SameSite=Lax is the Laravel default, and it quietly protects you from CSRF. So why do I keep finding SameSite=None in the apps I audit? Let's talk about what it does and how to use it safely.

By Stephen Rees-Carter 03 Aug 2026

Securing Laravel

The essential security resource for Laravel developers.

Securing Laravel
  • Subscribe
  • In Depth Articles
  • Security Tips
  • Archives
  • Stephen's Socials
Powered by Ghost