Securing Laravel
  • Home
  • In Depth Articles
  • Security Tips
  • Archives
  • About
  • Laravel Security Audits & Pentests
  • Practical Laravel Security Course
Sign in Subscribe
Newsletter

Don't miss the Laracon Online Discount!

Subscribe now to get 25% off your Laravel Security In Depth subscription!

Stephen Rees-Carter

Stephen Rees-Carter

28 Sep 2022 — 1 min read
Share
Don't miss the Laracon Online Discount!

This post is for subscribers only

Subscribe now

Already have an account? Sign in

Read more

In Depth: Don't Trust Public Livewire Properties

In Depth: Don't Trust Public Livewire Properties

[In Depth #39] Public Properties may look like PHP class properties, but they're really hidden form fields, just waiting for your input... 😈

lock-1 By Stephen Rees-Carter 18 Apr 2026
Security Tip: Stop Putting Actions on GET Requests!

Security Tip: Stop Putting Actions on GET Requests!

[Tip #128] Do you know the difference between GET and POST requests, and why it's so important that GET requests only ever retrieve data?

By Stephen Rees-Carter 17 Mar 2026
Security Tip: Your JWT Might Be a Forever Key!

Security Tip: Your JWT Might Be a Forever Key!

[Tip #127] Without an `exp` claim, a JWT can remain valid forever, turning a leaked token into permanent access.

By Stephen Rees-Carter 09 Mar 2026
Security Tip: Validate Config at Boot

Security Tip: Validate Config at Boot

[Tip #126] Rather than checking for essential config when it's used, throw the checks in your Service Provider - you'll know about configuration failures before your users get a weird error.

By Stephen Rees-Carter 02 Mar 2026
Securing Laravel
  • Subscribe
  • In Depth Articles
  • Security Tips
  • Archives
  • Stephen's Socials
Powered by Ghost

Securing Laravel

The essential security resource for Laravel developers.