Download the PHP package mnb/mnb-secure-core without Composer

On this page you can find all versions of the php package mnb/mnb-secure-core. It is possible to download/install these versions without Composer. Possible dependencies are resolved automatically.

FAQ

After the download, you have to make one include require_once('vendor/autoload.php');. After that you have to import the classes with use statements.

Example:
If you use only one package a project is not needed. But if you use more then one package, without a project it is not possible to import the classes with use statements.

In general, it is recommended to use always a project to download your libraries. In an application normally there is more than one library needed.
Some PHP packages are not free to download and because of that hosted in private repositories. In this case some credentials are needed to access such packages. Please use the auth.json textarea to insert credentials, if a package is coming from a private repository. You can look here for more information.

  • Some hosting areas are not accessible by a terminal or SSH. Then it is not possible to use Composer.
  • To use Composer is sometimes complicated. Especially for beginners.
  • Composer needs much resources. Sometimes they are not available on a simple webspace.
  • If you are using private repositories you don't need to share your credentials. You can set up everything on our site and then you provide a simple download link to your team member.
  • Simplify your Composer build process. Use our own command line tool to download the vendor folder as binary. This makes your build process faster and you don't need to expose your credentials for private repositories.
Please rate this library. Is it a good library?

Informations about the package mnb-secure-core

MNB Secure Core

Package: mnb/mnb-secure-core
Version: v1.0.1
Type: reusable no-framework PHP security library
PHP: 8.1+
License: MIT
Author: Nagendra babu Macharla (www.linkedin.com/in/nagendra-babu-macharla-55b703152)

MNB Secure Core is a reusable PHP security foundation for custom applications that do not depend on a framework. It is designed for admin panels, APIs, school/ERP systems, CRM tools, billing platforms, file tools, reporting dashboards, and other PHP applications that need production-grade security building blocks without adopting Laravel/Symfony/Slim as a hard dependency.

The current v1.0.1 release line includes request security, authentication, authorization, data protection, file safety, database governance, runtime command safety, outbound network/SSRF protection, security verification, safe errors, memory safety, throughput/capacity governance, origin protection, async queues, token/session control, XSS enforcement, and final production readiness tooling.


Why use MNB Secure Core

MNB Secure Core helps PHP teams add serious application security without rebuilding the same controls again and again for every project. The library is especially useful for no-framework apps, shared-hosting projects, custom admin panels, API backends, ERP/CRM systems, education platforms, file tools, and internal business applications.

Key advantages:

Advantage Benefit
No-framework design Works with plain PHP projects and can also be integrated into existing frameworks.
Central security kernel Gives one consistent entry point for request, auth, database, files, logs, queues, sessions, and production checks.
Security-by-policy approach High-risk actions such as SQL, schema changes, command execution, outbound HTTP, queues, and sessions are controlled by explicit policies.
Faster secure development Reduces the need to manually build CSRF, rate limits, data masking, upload validation, audit logs, safe errors, token revocation, and production checks.
Safer production defaults Encourages deny-by-default behavior, allow-lists, secret redaction, private storage, safe headers, and release-gate checks.
Tenant and role awareness Helps protect multi-tenant systems by connecting trust zones, authorization, database policies, cache keys, files, sessions, and audit events.
Full lifecycle protection Covers incoming requests, business operations, background jobs, outbound integrations, runtime execution, monitoring, verification, and release readiness.
Built-in diagnostics Provides CLI checks, demos, vulnerability reports, readiness checks, coverage reports, and release build planning.
Safer logs and evidence Keeps frontend responses clean while preserving redacted technical logs, audit records, pentest evidence, and incident response context.
Composer installation Installs cleanly from Packagist with composer require mnb/mnb-secure-core.

For more detailed feature documentation and code examples, refer to the docs/ directory. For runnable usage samples, refer to the examples/ and demos/ directories.


Current release status

Latest local validation from the current v1.0.1 upgrade line:

Check Result
PHP lint Passed
Test suite 398 passed, 0 failed
Demo suite Passed
Config validation Passed
Vulnerability score 99.05
Vulnerability grade A+

Production doctor/readiness results still depend on your real .env, secrets, HTTPS, CDN/proxy, storage paths, database user, and deployment firewall settings.


What this package protects

MNB Secure Core is organized as security engines. Each engine can be used independently, or through Mnb\SecurityCore\Core\SecurityKernel.

Area Main protection
Trust zones Request, tenant, user, role, data-class, and resource boundary checks
Request receiving Trusted hosts/proxies, HTTPS, request size, method/content checks, JSON parsing, suspicious request detection
Authentication Bearer/API/session/webhook/internal authentication strategies
Authorization Permissions, scopes, roles, ownership, tenant isolation, field-level filtering
Data protection Encryption, masking, search hashes, redaction, export protection
Web security Escaping, HTML sanitization, CSP/security headers, safe redirects, signed URLs, secure cookies
API/rate limiting Token scopes, rate policies, abuse throttling
File security Upload validation, private storage, malware scanner hooks, protected downloads, retention cleanup
Cache strategy Tenant-aware keys, TTLs, encryption for sensitive cache policies, invalidation, stampede guard
Secrets .env loading, secret inventory, redaction, scanning, rotation reports
Logging/audit/monitoring JSONL logs, tamper-evident audit, metrics, alerts, retention
Backup/recovery/incident Encrypted/signed backups, restore dry-runs, playbooks, evidence collection
Vulnerability matrix OWASP/CWE-style vulnerability coverage mapping, gaps, recommendations
Database governance Policy-based CRUD/search/alter, tenant scoping, query limits, schema plans, result masking
Runtime/network Safe process runner, command allow-listing, outbound HTTP guard, SSRF/DNS/redirect protections
Verification/remediation Pentest checklist, evidence bundles, SLA plans, retest gates, release gates
Safe errors Safe public responses, hidden technical logs, problem+JSON, log redaction, error fingerprinting
Memory/resource safety Operation memory profiles, stream guards, bounded buffers, temp file budgets, worker leak checks
Throughput/capacity Latency budgets, concurrency limiting, adaptive throttling, queue pressure, SLO and capacity gates
Origin protection Direct IP Host blocking, trusted proxy validation, fingerprint stripping, leak scanning, firewall guidance
Queue/background jobs Async dispatch, 202 responses, idempotency, retries, dead-letter queue, worker supervision
Token/session control Token revocation, refresh rotation, session registry, forced logout, remember-me safety
Final readiness/XSS Safe template rendering, unsafe output scan, production checklist, release build planning

Requirements

Required:

Recommended/optional:

Check your PHP environment:


Installation

Option A: direct library placement

Recommended for no-framework apps and shared hosting:

Bootstrap:

Option B: Composer / Packagist

Install from Packagist:

Composer bootstrap:

For local path development only:


First setup

Copy config and environment files. For Composer installs, the package lives under vendor/mnb/mnb-secure-core:

For direct library placement, use:

Create private storage:

Generate keys and validate:

For direct library placement, replace vendor/mnb/mnb-secure-core with libraries/mnb-secure-core.

Recommended production .env values:

Never commit real .env secrets.


Recommended middleware order

Use this general order for web/API entrypoints:

For easier setup, use the Secure Request Receiving profiles:

Common profiles include:


Common usage patterns

API token and rate limit

CSRF for browser forms

Authorization and tenant safety

Data protection

Secure database search

File upload and protected download

Runtime command safety and outbound SSRF protection

Safe errors

Public responses stay clean while technical details go to hidden, redacted logs with request IDs.

XSS-safe rendering

Use TemplateSafeValue only for content that was explicitly sanitized or generated by trusted code.

Async queue dispatch

Token revocation and session control


CLI reference

Run commands from the package root, or prefix with the library path from your app.

Core

Vulnerability matrix

Database

Runtime and outbound network

Verification and release gates

Errors

Memory/resources

Throughput/capacity

Origin protection

Queue/background jobs

Token/session

Final readiness and XSS


Demos

Run all demos:

Run the browser demo:

Open:

Important demo files:

Demo File
Vulnerability Matrix demos/13-vulnerability-blocking-matrix.php
Secure Database demos/14-secure-database-connect-retrieval-update-delete-search-alter.php
Pentest / Verification demos/15-penetration-testing-security-verification.php
Safe Errors demos/16-error-handling-custom-errors-logs-hidden-frontend.php
Memory Safety demos/17-memory-management-resource-safety.php
Throughput Capacity demos/18-throughput-performance-capacity-management.php
Secure Request Strategy demos/20-secure-request-receiving-strategy.php
Runtime / Outbound Network demos/31-runtime-execution-outbound-network-security-engine.php
Database Governance demos/32-secure-database-governance-query-lifecycle-engine.php
Verification / Remediation demos/33-security-verification-remediation-evidence-automation-engine.php
Safe Error / Technical Logs demos/34-safe-error-response-technical-log-isolation-engine.php
Memory Governance demos/35-memory-governance-resource-safety-engine.php
Throughput Governance demos/36-throughput-governance-performance-capacity-engine.php
Origin Protection demos/37-origin-identity-protection-exposure-hardening-engine.php
Queue / Background Jobs demos/38-async-request-response-queue-background-job-engine.php
Token / Session Control demos/39-token-revocation-session-control-engine.php
Final Readiness / XSS / Release demos/40-final-production-readiness-xss-release-consolidation-patch.php

v1.0.1 upgrade consolidation

This release line keeps all upgrades under v1.0.1.

Upgrade Engine
27 Runtime Execution and Outbound Network Security Engine
28 Secure Database Governance and Query Lifecycle Engine
29 Security Verification, Remediation, and Evidence Automation Engine
30 Safe Error Response and Technical Log Isolation Engine
31 Memory Governance and Resource Safety Engine
32 Throughput Governance and Performance Capacity Engine
33 Origin Identity Protection and Exposure Hardening Engine
34 Async Request, Response Queue, and Background Job Orchestration Engine
35 Token Revocation and Session Control Engine
36 Final Production Readiness, XSS Enforcement, and Release Consolidation Patch

Patch ZIPs from upgrades 29–36 are intended to be applied in order. For public distribution, create one clean merged release archive instead of shipping many patch ZIPs.


Production checklist

Before deployment, confirm:


What PHP code cannot solve alone

Some controls require deployment configuration:


Release archive hygiene

Do not ship development/runtime data in public releases.

Exclude:

Keep placeholder .gitkeep files where needed.

A clean release can be created with Git:

Or use the release planning commands:


Public package safety note

MNB Secure Core provides reusable security building blocks. It does not automatically make an application secure unless the application integrates the controls correctly, configures production settings safely, and tests the final deployment.

Use the included demos, CLI diagnostics, release gates, and vulnerability matrix as proof-oriented safety tools, not as a substitute for secure application design, code review, and authorized penetration testing.


Security reporting

Report vulnerabilities privately using SECURITY.md. Do not disclose exploitable details in public GitHub issues.


All versions of mnb-secure-core with dependencies

PHP Build Version
Package Version
Requires php Version >=8.1
ext-openssl Version *
ext-fileinfo Version *
ext-json Version *
ext-pdo Version *
Composer command for our command line client (download client) This client runs in each environment. You don't need a specific PHP version etc. The first 20 API calls are free. Standard composer command

The package mnb/mnb-secure-core contains the following files

Loading the files please wait ...