Download the PHP package sagor/laravel-security without Composer

On this page you can find all versions of the php package sagor/laravel-security. It is possible to download/install these versions without Composer. Possible dependencies are resolved automatically.

FAQ

After the download, you have to make one include require_once('vendor/autoload.php');. After that you have to import the classes with use statements.

Example:
If you use only one package a project is not needed. But if you use more then one package, without a project it is not possible to import the classes with use statements.

In general, it is recommended to use always a project to download your libraries. In an application normally there is more than one library needed.
Some PHP packages are not free to download and because of that hosted in private repositories. In this case some credentials are needed to access such packages. Please use the auth.json textarea to insert credentials, if a package is coming from a private repository. You can look here for more information.

  • Some hosting areas are not accessible by a terminal or SSH. Then it is not possible to use Composer.
  • To use Composer is sometimes complicated. Especially for beginners.
  • Composer needs much resources. Sometimes they are not available on a simple webspace.
  • If you are using private repositories you don't need to share your credentials. You can set up everything on our site and then you provide a simple download link to your team member.
  • Simplify your Composer build process. Use our own command line tool to download the vendor folder as binary. This makes your build process faster and you don't need to expose your credentials for private repositories.
Please rate this library. Is it a good library?

Informations about the package laravel-security

sagor/laravel-security

DEVELOPED BY MOH SAGOR
Defense-in-Depth Application Security Firewall & Cyber Desk Workstation for Laravel

Latest Stable Version Total Downloads License PHP Version Laravel Version


⚡ Overview

sagor/laravel-security is a production-ready, high-performance defense-in-depth security package built for Laravel 5.5 through 13.x on PHP 7.2 through 8.4.

Created by Moh Sagor, it protects web endpoints, REST APIs, and file upload forms against OWASP Top 10 vulnerabilities including SQL Injection, Cross-Site Scripting (XSS), Path Traversal, Remote Command Execution, SSRF, Malicious File Uploads, Rate Abuse, and Automated Security Scanners.

It comes equipped with an interactive Cyber Command Center Dashboard and Cyber Desk All Attempts Workstation featuring live 24-hour database time-series charts, holographic payload inspector modals, sub-millisecond threat classification, and interactive Cyberpunk animations.


📋 Table of Contents


✨ Key Features


⚙️ Requirements & Compatibility

Component Supported Versions
PHP ^7.2, ^7.3, ^7.4, ^8.0, ^8.1, ^8.2, ^8.3, ^8.4
Laravel 5.5.x through 13.x
Database MySQL, PostgreSQL, SQLite, MariaDB
Cache Driver Redis, Memcached, Array, File, Database

🚀 Installation & Zero-Configuration Setup

⚡ Instant Setup (Zero Configuration Required)

sagor/laravel-security features Zero-Configuration Auto-Setup. Upon installation, the package automatically:

  1. Auto-registers Firewall Middleware (SecurityMiddleware and SecurityUploadMiddleware on web, SecurityApiMiddleware on api).
  2. Auto-loads Database Migrations for security audit tables.
  3. Auto-registers Workstation Routes (/security and /security/attempts).

That's it! Your application is now fully protected and the Cyber Desk is active at http://localhost:8000/security.


Optional Manual Publishing

If you wish to customize configuration or views, run the installer command:


🛡️ Middleware Configuration (Optional)

Laravel 11, 12, and 13 (bootstrap/app.php)

In modern Laravel applications, register the middleware aliases or append to middleware groups in bootstrap/app.php:

Laravel 5.5 through 10 (app/Http/Kernel.php)

Add the middleware to $routeMiddleware or $middlewareGroups in app/Http/Kernel.php:

Protecting Web & File Upload Routes (routes/web.php)


🖥️ Cyber Desk Workstation & Dashboard

Access the built-in security workstation in your web browser (Protected: Accessible ONLY to authenticated logged-in users):

🔒 Security Note: Unauthenticated guests attempting to visit these routes are automatically blocked with HTTP 403 Forbidden or redirected to the application login screen.

Features of the Cyber Desk:


🔍 Security Engines & Threat Rules

The package ships with 10 built-in security detection rules:

Rule Identifier Threat Vector Description
sqli.detector SQL Injection Detects UNION SELECT, stacked queries, blind sleep functions, boolean conditions
xss.detector Cross-Site Scripting Identifies <script>, inline event handlers (onload=, onerror=), javascript: URIs
path_traversal.detector Path Traversal Blocks ../, ..\\, /etc/passwd, Windows system file references
command_injection.detector Command Injection Intercepts shell metacharacters (\|, ;, $(...), nc, wget, curl, bash)
ssrf.detector SSRF Attack Blocks access to cloud metadata IPs (169.254.169.254), internal loopback (127.0.0.1)
scanner.detector Scanner Detection Identifies security tools (sqlmap, nikto, gobuster, dirbuster, nmap)
user_agent.detector Suspicious User-Agent Rejects empty, anomalous, or malicious User-Agent headers
request_size.detector Request Size Enforces maximum HTTP body payload boundaries
hpp.detector HTTP Parameter Pollution Detects duplicate key parameter pollution attacks
encoding.detector Double/Null Encoding Intercepts %00 null bytes and double URL encoding bypasses

📁 File Upload Protection & Quarantine

SecurityUploadMiddleware intercepts incoming file uploads and executes a 4-step security inspection:

  1. Magic Byte Signature Check: Compares binary header signatures (e.g. FF D8 FF for JPEG, 89 50 4E 47 for PNG, 25 50 44 46 for PDF) against the user-submitted file extension to block executable files disguised with fake extensions.
  2. Archive Bomb Check: Analyzes compressed archives (.zip) to prevent decompression bomb attacks exceeding safety expansion ratios (e.g. 100:1 ratio).
  3. Filename Sanitization: Strip dangerous extensions, double extensions (image.png.php), control characters, and null bytes.
  4. Quarantine Storage: Automatically moves rejected files to non-public quarantine storage at storage/app/security/quarantine/ with execution-blocking .htaccess controls and logs entries to both shield_security_events and shield_malware_scans.

⚙️ Configuration Reference (config/security.php)

Publish the configuration file using php artisan security:install:


🛠️ Artisan CLI Commands

Command Description
php artisan security:install Run installer, publish configuration, views, and migrations
php artisan security:status Display firewall engine health, active modes, and driver status
php artisan security:scan {path} Scan a target file or directory for malware signatures
php artisan security:routes Generate and display cryptographic obfuscated route mappings
php artisan security:clear Flush rate limit caches and temporary blocked IP records
php artisan security:report Generate a comprehensive application security summary report
php artisan security:cleanup Purge old security log records beyond configured retention days
php artisan security:test Run firewall engine self-test against attack payloads

🧩 Creating Custom Security Rules

You can easily extend the firewall by implementing the SecurityRule interface:

Register your custom rule in your AppServiceProvider:


🔒 Dynamic Route Encryption

sagor/laravel-security allows you to define standard Laravel routes as normal in routes/web.php, while dynamically displaying them as encrypted URLs in browser links, address bars, and forms.

1. Define Routes Normally in routes/web.php

2. Configure Target Encrypted Routes (config/security.php)

Add target route names or wildcard patterns to route_encryption.routes:

3. URL Generation & Blade Directives

In Blade templates or controllers, generate encrypted URLs using helpers or Blade directives:

When a user clicks the encrypted link (/e/eyJpZCI6NX0...), the package automatically decrypts the token, verifies MAC integrity, and dispatches the request to ProductController@edit($id) seamlessly!


📄 License & Credits


All versions of laravel-security with dependencies

PHP Build Version
Package Version
Requires php Version ^7.2 || ^7.3 || ^7.4 || ^8.0 || ^8.1 || ^8.2 || ^8.3 || ^8.4
illuminate/support Version ^5.5 || ^6.0 || ^7.0 || ^8.0 || ^9.0 || ^10.0 || ^11.0 || ^12.0 || ^13.0
illuminate/http Version ^5.5 || ^6.0 || ^7.0 || ^8.0 || ^9.0 || ^10.0 || ^11.0 || ^12.0 || ^13.0
illuminate/cache Version ^5.5 || ^6.0 || ^7.0 || ^8.0 || ^9.0 || ^10.0 || ^11.0 || ^12.0 || ^13.0
illuminate/routing Version ^5.5 || ^6.0 || ^7.0 || ^8.0 || ^9.0 || ^10.0 || ^11.0 || ^12.0 || ^13.0
illuminate/console Version ^5.5 || ^6.0 || ^7.0 || ^8.0 || ^9.0 || ^10.0 || ^11.0 || ^12.0 || ^13.0
illuminate/database Version ^5.5 || ^6.0 || ^7.0 || ^8.0 || ^9.0 || ^10.0 || ^11.0 || ^12.0 || ^13.0
Composer command for our command line client (download client) This client runs in each environment. You don't need a specific PHP version etc. The first 20 API calls are free. Standard composer command

The package sagor/laravel-security contains the following files

Loading the files please wait ...