Download the PHP package laruence/taint without Composer

On this page you can find all versions of the php package laruence/taint. It is possible to download/install these versions without Composer. Possible dependencies are resolved automatically.

FAQ

After the download, you have to make one include require_once('vendor/autoload.php');. After that you have to import the classes with use statements.

Example:
If you use only one package a project is not needed. But if you use more then one package, without a project it is not possible to import the classes with use statements.

In general, it is recommended to use always a project to download your libraries. In an application normally there is more than one library needed.
Some PHP packages are not free to download and because of that hosted in private repositories. In this case some credentials are needed to access such packages. Please use the auth.json textarea to insert credentials, if a package is coming from a private repository. You can look here for more information.

  • Some hosting areas are not accessible by a terminal or SSH. Then it is not possible to use Composer.
  • To use Composer is sometimes complicated. Especially for beginners.
  • Composer needs much resources. Sometimes they are not available on a simple webspace.
  • If you are using private repositories you don't need to share your credentials. You can set up everything on our site and then you provide a simple download link to your team member.
  • Simplify your Composer build process. Use our own command line tool to download the vendor folder as binary. This makes your build process faster and you don't need to expose your credentials for private repositories.
Please rate this library. Is it a good library?

Informations about the package taint

Taint

linux windows

A PHP extension to detect XSS codes(tainted strings). It can also be used to spot SQL injection vulnerabilities, shell injection, etc.

The idea comes from https://wiki.php.net/rfc/taint, and I implemented it as a PHP extension, so no core patch is needed.

Please do not enable this extension in production environments, since it will slow down your app.

EXPERIMENTAL. Taint is a research-grade detection tool, not a security product. Detection coverage, warning behavior and INI settings may change between releases without any backward-compatibility guarantees.

Requirements

How it works

Strings received from user input are marked "tainted" at request startup, and the mark is tracked through string operations. When a tainted string reaches a dangerous sink (output, SQL query, shell command, file path, ...), taint raises a warning.

Taint sources are: $_GET, $_POST and $_COOKIE.

Design philosophy

When to use

Good fits:

Not a good fit:

NOTE

Taint works by installing user opcode handlers and swapping internal function handlers. That makes it incompatible with the OPcache JIT — but not with OPcache itself:

Taint is a detection tool for development use and is not designed for production deployment anyway.

Install

Install via PECL

Taint is a PECL extension, simply install it by:

`

Compile from source

`

Usage

When taint is enabled, if you pass a tainted string(which comes from $_GET, $_POST or $_COOKIE) to some dangerous functions, taint will warn you about that.

``

The above example will output something similar to: `

Detected sinks

Category Checked
Output echo, print, printf, vprintf, print_r, var_dump, var_export, exit/die with a message, file_put_contents() to php://output
Filesystem fopen, unlink, file, readfile, file_get_contents, highlight_file, show_source, opendir, file_put_contents, copy, rename, move_uploaded_file, mkdir, rmdir, touch, include, include_once, require, require_once
SQL mysqli_query, mysqli_prepare, mysqli_real_query, mysqli_multi_query, mysql_query, sqlite_query, sqlite_single_query, oci_parse, pg_query, pg_send_query; methods mysqli::query/prepare/real_query/multi_query, PDO::query/prepare/exec, SQLite3::query/prepare/exec, SQLiteDatabase::query/singleQuery
Command exec, system, passthru, shell_exec(including the backtick operator), proc_open, popen
Code execution eval, dynamic calls $func(), call_user_func, $obj->$method(), array callables [$obj, "m"]() / ["C", "m"](), callback name passed to preg_replace_callback
Header/Cookie header, setcookie, setrawcookie
Other unserialize, mail(to, subject, additional_params and additional_headers)

Checks are shallow on purpose: only top-level string arguments are inspected, so dumping an array that contains tainted values does not warn.

Taint propagation

The taint mark survives string concatenation(., "{$var}" interpolation, .=) and these functions(both the plain call and the PHP 8.4+ frameless fast paths):

trim, rtrim, ltrim, substr, strstr, str_replace, str_ireplace, str_pad, sprintf, vsprintf, implode, join, explode, strtolower, strtoupper, strval, dirname, basename, pathinfo

For sprintf/vsprintf only %s specifiers carry the mark through — sprintf("%d", $t) produces a clean string, since numeric specifiers emit derived values, not the original bytes.

Any other function call produces a fresh, unmarked string — including escaping helpers such as htmlspecialchars(). Taint is a single, context-independent bit by design: it is meant to over-report during development rather than to understand which context a string is safe in.

API

Taint registers three global functions and no classes or constants.

``

Manually mark variables as tainted (by reference). Always returns true. Only non-empty strings are marked; other types and empty strings are silently ignored. When taint.enable is off, this is a no-op (still returns true). The mark lives on the string itself, so assignments just share it.

``

Clear the mark. Since the bit lives on the string itself, every copy/reference sharing the same string becomes clean at once. Always returns true.

``

Check whether a value carries the taint mark. Only strings can be tainted, other types return false. Always returns false when taint.enable is off.

``

INI settings

Name Default Changeable Description
taint.enable 0 PHP_INI_SYSTEM master switch
taint.error_level 512 (E_USER_WARNING) PHP_INI_ALL error level used for warnings

If you need to hide the errors for a particular script, you can: `

License

Taint is distributed under the PHP-3.01 license.


All versions of taint with dependencies

PHP Build Version
Package Version
Requires php Version >=8.0
Composer command for our command line client (download client) This client runs in each environment. You don't need a specific PHP version etc. The first 20 API calls are free. Standard composer command

The package laruence/taint contains the following files

Loading the files please wait ...