Securing Laravel
  • Home
  • In Depth Articles
  • Security Tips
  • Archives
  • About
  • Laravel Security Audits & Pentests
  • Practical Laravel Security Course
Sign in Subscribe
Restack

OpenLampTech - Developer Interview with Stephen Rees-Carter

Joshua Otwell

29 Jun 2023

Read more

Security Tip: Consider All Routes, Not Just Web!

Security Tip: Consider All Routes, Not Just Web!

[Tip #125] routes/web.php is boring and reliable, and routes/api.php is fancy, but have you forgotten one?

By Stephen Rees-Carter 14 Feb 2026
Security Tip: Update your packages! (Yes, this again!)

Security Tip: Update your packages! (Yes, this again!)

[Tip #124] I know I say this all the time (especially on stage!), but apparently not everyone heard me, so here we go again...

By Stephen Rees-Carter 04 Feb 2026
Security Tip: How Should APIs Respond to HTTP?

Security Tip: How Should APIs Respond to HTTP?

[Tip #123] If an API client tries to connect via unencrypted HTTP, what should your API do: redirect to HTTPS, disable HTTP, offer a swift rebuke, or take matters into it's own hands?

By Stephen Rees-Carter 29 Sep 2025
Security Tip: Bypassing Content-Security-Policy with <base>!

Security Tip: Bypassing Content-Security-Policy with <base>!

[Tip #122] Content Security Policies are awesome, but if you haven't fully configured all of your directives, it's possible to redirect requests, inherit Nonces, and get juicy CSP-bypassing XSS! 😈

By Stephen Rees-Carter 15 Sep 2025
Securing Laravel
  • Subscribe
  • In Depth Articles
  • Security Tips
  • Archives
  • Stephen's Socials
Powered by Ghost

Securing Laravel

The essential security resource for Laravel developers.