Skip to content
Discussion options

You must be logged in to vote

Laravel security checklist:

  1. Mass Assignment - check $fillable/$guarded
  2. SQL Injection - use Eloquent ORM
  3. XSS - use {{ }} not {!! !!}
  4. CSRF - ensure @csrf on forms
  5. APP_DEBUG=false in production
  6. Strong APP_KEY
  7. HTTPS enforced
  8. Rate limiting on auth

Tools: OWASP ZAP, Burp Suite, Laravel Security Checker

Happy to help with specifics!

Replies: 3 comments

Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Answer selected by anggi135
Comment options

You must be logged in to vote
0 replies
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Code Security Build security into your GitHub workflow with features to keep your codebase secure General General topics and discussions that don't fit into other categories, but are related to GitHub
2 participants