Libraries tagged by php security
sylius/rbac
35910 Downloads
RBAC component for PHP applications.
stormpath/sdk
60195 Downloads
A PHP wrapper for Stormpath's API
paragonie/airship
10 Downloads
Simply Secure Content Management System - 'The sky is only the beginning'
maikuolan/phpmussel
190 Downloads
PHP-based anti-virus anti-trojan anti-malware solution.
leigh/curve25519
26052 Downloads
Pure PHP implementation of the Curve25519 Diffie-Hellman function
danog/tgseclib
435475 Downloads
PHP Secure Communications Library (+Telegram-specific AES IGE primitives) - Pure-PHP implementations of RSA, AES, SSH2, SFTP, X.509 etc.
php-opcua/opcua-client
1405 Downloads
Pure PHP OPC UA client — binary protocol over TCP, 6 security policies, browse/read/write/subscribe/history, zero external dependencies
simplesamlphp/xml-wss-core
1871 Downloads
WS-Security PHP library
palepurple/nmap
3607 Downloads
nmap is a PHP wrapper for Nmap, a free security scanner for network exploration. This is (mostly) a fork of willdurand/nmap with PHP 7 and vimeo/psalm static analysis improvements.
voku/session2db
19965 Downloads
A PHP library acting as a wrapper for PHP's default session handling functions which stores data in a MySQL database, providing both better performance and better security and protection against session fixation and session hijacking.
yousha/php-security-linter
325 Downloads
A PHP tool to lint PHP files for security issues based on CIS and OWASP best practices.
vartroth/php-security-lint
546 Downloads
A PHP security linter to detect insecure functions like var_dump, print_r, and other dangerous functions in your codebase
move-elevator/local-php-security-checker-installer
12374 Downloads
Composer integration for local PHP security check
marektichy/totp-php
71 Downloads
Lightweight, fast, and secure TOTP (2FA) authentication library for PHP — battle tested, dependency free, and ready for enterprise integration.
laramint/php-security-scanner
674 Downloads
Framework-agnostic static security scanner for PHP. Detects SQLi, XSS, command injection, path traversal, insecure deserialization, weak crypto, hardcoded secrets, and more.