Securing Laravel
  • Home
  • In Depth Articles
  • Security Tips
  • Archives
  • About
  • Laravel Security Audits & Pentests
  • Practical Laravel Security Course
Sign in Subscribe
Newsletter

Laravel Security in Depth > Black Friday > 25% / 50% off > Forever ⭐

Get 25% off individual subscriptions, or 50% off teams. Forever.

Stephen Rees-Carter

Stephen Rees-Carter

26 Nov 2021 — 2 min read
Share
Laravel Security in Depth > Black Friday > 25% / 50% off > Forever ⭐

This post is for subscribers only

Subscribe now

Already have an account? Sign in

Read more

Security Tip: The Signed URL Trap

Security Tip: The Signed URL Trap

[Tip #129] I love Signed URLs, but there is one very subtle trap you can accidentally fall into...

By Stephen Rees-Carter 28 Apr 2026
In Depth: Don't Trust Public Livewire Properties

In Depth: Don't Trust Public Livewire Properties

[In Depth #39] Public Properties may look like PHP class properties, but they're really hidden form fields, just waiting for your input... 😈

lock-1 By Stephen Rees-Carter 18 Apr 2026
Security Tip: Stop Putting Actions on GET Requests!

Security Tip: Stop Putting Actions on GET Requests!

[Tip #128] Do you know the difference between GET and POST requests, and why it's so important that GET requests only ever retrieve data?

By Stephen Rees-Carter 17 Mar 2026
Security Tip: Your JWT Might Be a Forever Key!

Security Tip: Your JWT Might Be a Forever Key!

[Tip #127] Without an `exp` claim, a JWT can remain valid forever, turning a leaked token into permanent access.

By Stephen Rees-Carter 09 Mar 2026
Securing Laravel
  • Subscribe
  • In Depth Articles
  • Security Tips
  • Archives
  • Stephen's Socials
Powered by Ghost

Securing Laravel

The essential security resource for Laravel developers.