Download the PHP package wazza/laravel-db-encryption without Composer
On this page you can find all versions of the php package wazza/laravel-db-encryption. It is possible to download/install these versions without Composer. Possible dependencies are resolved automatically.
Download wazza/laravel-db-encryption
More information about wazza/laravel-db-encryption
Files in wazza/laravel-db-encryption
Package laravel-db-encryption
Short Description Production-ready Laravel package for secure, transparent encryption of sensitive model attributes with searchable hash indexes and key rotation support.
License MIT
Homepage https://www.wazzac.dev
Informations about the package laravel-db-encryption
Laravel DB Encryption
A production-ready Laravel package for secure, transparent encryption of sensitive model attributes. Store encrypted data in a dedicated table while keeping your main tables clean and performant.
π Why This Package?
- Transparent Encryption: Automatic encryption/decryption via Eloquent trait
- Separate Storage: Encrypted data stored in dedicated
encrypted_attributestable - Searchable: Filter encrypted data using SHA-256 hash indexes
- Zero Configuration: Works out of the box with sensible defaults
- Production Ready: Comprehensive error handling, logging, and security features
- Performance: Batch operations and optimized queries
- Compliance Ready: Helps meet GDPR, HIPAA, PCI DSS requirements
π Requirements
- PHP: 8.2 or higher
- Laravel: 12.x
- OpenSSL: PHP OpenSSL extension
π Installation
1. Install via Composer
2. Publish Configuration & Migrations
3. Generate Encryption Key
This adds DB_ENCRYPT_KEY to your .env file.
4. Run Migrations
π Usage
Basic Setup
Add the HasEncryptedAttributes trait to your model and define which attributes should be encrypted:
Working with Encrypted Attributes
Searching Encrypted Data
Use the whereEncrypted scope to search encrypted attributes:
Using the Facade
For direct encryption/decryption operations:
π οΈ Advanced Features
Artisan Commands
Generate Encryption Key
Re-encrypt Data (Key Rotation)
Prune Orphaned Records
Configuration
Edit config/db-encrypt.php:
Custom Exceptions
The package provides specific exceptions for better error handling:
π Security Best Practices
1. Key Management
- Never commit encryption keys to version control
- Use different keys for each environment
- Rotate keys periodically using
db-encrypt:re-encrypt - Consider using a Key Management Service (KMS) in production
2. What to Encrypt
β Good candidates:
- Social Security Numbers
- Credit card numbers
- Passwords (though hashing is usually better)
- Medical records
- Personal identification numbers
- Private notes
β Bad candidates:
- Primary keys or foreign keys
- Data you need to sort by
- Data used in mathematical operations
- High-cardinality lookup values
3. Performance Considerations
- Encryption adds overheadβonly encrypt truly sensitive data
- Use indexes on your main tables for performance
- Consider caching decrypted data for read-heavy operations
- Use batch operations when encrypting/decrypting multiple values
4. Backup Strategy
- Always backup before key rotation
- Test key rotation in staging first
- Keep old keys until you verify re-encryption succeeded
See SECURITY.md for comprehensive security guidelines.
π§ͺ Testing
π Troubleshooting
"Encryption key is not set"
Solution: Run php artisan db-encrypt:generate-key or manually set DB_ENCRYPT_KEY in .env
"Cannot encrypt attribute 'name' because it exists as a column"
Solution: Encrypted properties must NOT exist as database columns. Remove the column or choose a different property name.
"Decryption failed"
Possible causes:
- Wrong encryption key
- Corrupted data
- Key was rotated but data wasn't re-encrypted
Solution:
- Verify
DB_ENCRYPT_KEYis correct - Check logs for detailed error messages
- Restore from backup if data is corrupted
Performance issues
Solutions:
- Ensure indexes are created on
encrypted_attributestable (done automatically) - Reduce logging level in production (
DB_ENCRYPT_LOG_LEVEL=0) - Use batch operations for multiple encryptions
- Consider caching frequently accessed encrypted data
Search not finding records
Check:
- Ensure you're using
whereEncrypted()scope - Verify the exact value (encryption is case-sensitive)
- Check that hash_index was generated correctly
π Monitoring
View Package Logs
Check Encryption Status
π€ Contributing
Contributions are welcome! Please see CONTRIBUTING.md for details.
- Fork the repository
- Create your feature branch (
git checkout -b feature/amazing-feature) - Write tests for your changes
- Ensure all tests pass (
./vendor/bin/pest) - Commit your changes (
git commit -m 'Add amazing feature') - Push to the branch (
git push origin feature/amazing-feature) - Open a Pull Request
π License
This package is open-sourced software licensed under the MIT license.
π¨βπ» Author
Warren Coetzee
- Website: wazzac.dev
- Email: [email protected]
- GitHub: @wazzac
π Acknowledgments
- Built for the Laravel community
- Inspired by the need for simple, secure database encryption
- Thanks to all contributors and users
β Support
If this package helps you, consider buying me a coffee!
π Changelog
See CHANGELOG.md for what has changed recently.
π‘οΈ Security
Please review our security policy for reporting security vulnerabilities.
Made with β€οΈ for the Laravel community
All versions of laravel-db-encryption with dependencies
ext-openssl Version *
illuminate/support Version ^12.0
illuminate/database Version ^12.0
illuminate/console Version ^12.0
php Version ^8.2 || ^8.3