Secure a PHP web app by keeping its runtime and dependencies supported, hardening production settings, and enforcing protections at each boundary: login, permissions, input, database queries, sessions, and responses. These eight practices synthesize current PHP and OWASP guidance; adapt the details to your PHP version, framework, deployment, and threat model.
1. Keep PHP and dependencies supported
Running a supported PHP branch is a basic security control: once upstream security support ends, that branch no longer receives upstream security fixes. The PHP Group’s supported versions page, checked September 30, 2026, listed these branches as supported:
| PHP branch | Upstream security support ends |
|---|---|
| 8.2 | December 31, 2026 |
| 8.3 | December 31, 2027 |
| 8.4 | December 31, 2028 |
| 8.5 | December 31, 2029 |
These dates describe upstream support, not necessarily the support policy of a hosting provider or operating-system distributor. Check the live PHP lifecycle table before planning an upgrade, and schedule the move before your branch reaches its security-support end date. Keep frameworks and other dependencies maintained as well; an old or abandoned dependency can undermine an otherwise current runtime.
Make upgrades part of routine maintenance
Track the PHP version used in production, test upgrades in a staging environment, and verify that application code and dependencies work with the target branch. Treat dependency updates similarly: review what changed, run the application’s tests, and deploy through a controlled process rather than letting production drift indefinitely.
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →#1 Best Overall
- DUAL-BAND WIFI 6 ROUTER: Wi-Fi 6(802.11ax) technology achieves faster speeds, greater capacity and reduced network congestion compared to the previous gen. All WiFi routers require a separate modem. Dual-Band WiFi routers do not support the 6 GHz band.
- AX1800: Enjoy smoother and more stable streaming, gaming, downloading with 1.8 Gbps total bandwidth (up to 1200 Mbps on 5 GHz and up to 574 Mbps on 2.4 GHz). Performance varies by conditions, distance to devices, and obstacles such as walls.
- CONNECT MORE DEVICES: Wi-Fi 6 technology communicates more data to more devices simultaneously using revolutionary OFDMA technology
- EXTENSIVE COVERAGE: Achieve the strong, reliable WiFi coverage with Archer AX1800 as it focuses signal strength to your devices far away using Beamforming technology, 4 high-gain antennas and an advanced front-end module (FEM) chipset
- OUR CYBERSECURITY COMMITMENT: TP-Link is a signatory of the U.S. Cybersecurity and Infrastructure Security Agency’s (CISA) Secure-by-Design pledge. This device is designed, built, and maintained, with advanced security as a core requirement.
2. Harden production configuration and error handling
Production should not display diagnostic errors to visitors. Configure PHP to log errors instead, then ensure logs are accessible only to the people and systems that need them.
display_errors = Off
log_errors = On
These are starting points, not a complete production configuration. Choose log destinations, file permissions, retention, upload limits, session settings, and other values for your actual deployment. Keep secrets and sensitive configuration out of public directories and source control, and make sure error messages shown to users do not reveal paths, SQL details, credentials, or internal implementation.
Review the PHP configuration and the framework or hosting platform’s production guidance together. A setting applied in the wrong configuration file or overridden by the hosting environment may not affect the running application.
3. Protect authentication and passwords
Use a maintained framework or authentication implementation instead of building the entire login flow yourself. Serve login pages, credential submissions, and the authenticated experience over TLS; protecting only the initial password submission is not enough if later authenticated traffic can be intercepted or altered.
Free tools Windows power users keep installed
One-click scans. No signup required.
Rank #2
- Dual-band Wi-Fi with 5 GHz speeds up to 867 Mbps and 2.4 GHz speeds up to 300 Mbps, delivering 1200 Mbps of total bandwidth¹. Dual-band routers do not support 6 GHz. Performance varies by conditions, distance to devices, and obstacles such as walls.
- Covers up to 1,000 sq. ft. with four external antennas for stable wireless connections and optimal coverage.
- Supports IGMP Proxy/Snooping, Bridge and Tag VLAN to optimize IPTV streaming
- Access Point Mode - Supports AP Mode to transform your wired connection into wireless network, an ideal wireless router for home
- Advanced Security with WPA3 - The latest Wi-Fi security protocol, WPA3, brings new capabilities to improve cybersecurity in personal networks
Store password hashes, never plaintext passwords, and do not write passwords to application logs. PHP’s password API provides the basic operations:
$hash = password_hash($password, PASSWORD_DEFAULT);
if (password_verify($submittedPassword, $hash)) {
// Continue the sign-in flow.
}
Use the current PHP documentation to guide implementation and keep hashes in a field that can accommodate changes in the default algorithm. Do not choose a work factor by copying an unverified number; tune and review password-storage settings for the PHP version and system you operate.
Require a fresh authentication check before particularly sensitive account changes, such as changing a password or recovery details. This reduces the damage possible if someone gains access to an unattended, already-authenticated session.
4. Authorize every requested action and resource
Authentication establishes who is signed in; authorization determines whether that person may perform a specific action on a specific resource. Check permissions on the server for every request. A hidden button or a client-side route restriction is only a user-interface choice, not an access-control boundary.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteRank #3
- NIGHTHAWK WIFI 6 ROUTER FOR YOUR WHOLE HOME: Delivers fast, reliable WiFi across every room of your apartment or small home for streaming, gaming, video calls, and smart home devices, all running at the same time without slowing each other down.
- WORKS WITH YOUR EXISTING INTERNET SERVICE: Pairs with your existing modem or gateway via ethernet. Compatible with most cable, fiber, DSL, and satellite providers. Some gateways and modem router combos may require bridge mode. No coax needed.
- SET UP AND MANAGE YOUR NETWORK WITH THE NIGHTHAWK APP: Download the free Nighthawk app on iOS or Android for guided setup. Manage WiFi, run speed tests, pause devices, and set up guest networks from anywhere. Active internet required.
- READY FOR THE DEVICES YOU ALREADY OWN: Your phones, laptops, and TVs work right out of the box. WiFi 6 delivers speeds up to 1.8 Gbps across 2.4 GHz and 5 GHz bands. Backward compatible with WiFi 5 and earlier.
- COVERAGE IN EVERY ROOM: Covers up to 1,500 sq. ft. for up to 20 connected devices. Walls, floors, and interference can reduce range. Larger or multi-story homes may benefit from a NETGEAR Orbi mesh WiFi system.
Check ownership as well as role
For a request to view or edit a record, verify that the current user is allowed to access that particular record. A user who may edit their own profile should not gain access to another person’s profile merely by changing an ID in a URL or request body. Apply the same principle to administrative actions, downloads, APIs, and background operations.
Make access-control checks close to the operation they protect, and test both allowed and denied cases. An authenticated user can still be unauthorized for an individual action or resource.
5. Validate untrusted input and encode output for its context
Validate data as soon as it enters the application, including data from APIs, imports, and other services—not just browser forms. OWASP recommends validating both syntax (for example, whether a date is correctly formed) and semantics (whether that date makes sense for the requested operation).
Validation helps reject malformed or out-of-range values, but it is not a universal security filter. It does not replace parameterized SQL for injection prevention or context-appropriate output encoding for cross-site scripting (XSS). When displaying untrusted text in HTML, encode it for the exact output context rather than assuming a generic “sanitize everything” step is sufficient.
Rank #4
- 𝐅𝐮𝐭𝐮𝐫𝐞-𝐏𝐫𝐨𝐨𝐟 𝐘𝐨𝐮𝐫 𝐇𝐨𝐦𝐞 𝐖𝐢𝐭𝐡 𝐖𝐢-𝐅𝐢 𝟕: Powered by Wi-Fi 7 technology, enjoy faster speeds with Multi-Link Operation, increased reliability with Multi-RUs, and more data capacity with 4K-QAM, delivering enhanced performance for all your devices.
- 𝐁𝐄𝟑𝟔𝟎𝟎 𝐃𝐮𝐚𝐥-𝐁𝐚𝐧𝐝 𝐖𝐢-𝐅𝐢 𝟕 𝐑𝐨𝐮𝐭𝐞𝐫: Delivers up to 2882 Mbps (5 GHz), and 688 Mbps (2.4 GHz) speeds for 4K/8K streaming, AR/VR gaming & more. Dual-band routers do not support 6 GHz. Performance varies by conditions, distance, and obstacles like walls.
- 𝐔𝐧𝐥𝐞𝐚𝐬𝐡 𝐌𝐮𝐥𝐭𝐢-𝐆𝐢𝐠 𝐒𝐩𝐞𝐞𝐝𝐬 𝐰𝐢𝐭𝐡 𝐃𝐮𝐚𝐥 𝟐.𝟓 𝐆𝐛𝐩𝐬 𝐏𝐨𝐫𝐭𝐬 𝐚𝐧𝐝 𝟑×𝟏𝐆𝐛𝐩𝐬 𝐋𝐀𝐍 𝐏𝐨𝐫𝐭𝐬: Maximize Gigabitplus internet with one 2.5G WAN/LAN port, one 2.5 Gbps LAN port, plus three additional 1 Gbps LAN ports. Break the 1G barrier for seamless, high-speed connectivity from the internet to multiple LAN devices for enhanced performance.
- 𝐍𝐞𝐱𝐭-𝐆𝐞𝐧 𝟐.𝟎 𝐆𝐇𝐳 𝐐𝐮𝐚𝐝-𝐂𝐨𝐫𝐞 𝐏𝐫𝐨𝐜𝐞𝐬𝐬𝐨𝐫: Experience power and precision with a state-of-the-art processor that effortlessly manages high throughput. Eliminate lag and enjoy fast connections with minimal latency, even during heavy data transmissions.
- 𝐂𝐨𝐯𝐞𝐫𝐚𝐠𝐞 𝐟𝐨𝐫 𝐄𝐯𝐞𝐫𝐲 𝐂𝐨𝐫𝐧𝐞𝐫 - Covers up to 2,000 sq. ft. for up to 60 devices at a time. 4 internal antennas and beamforming technology focus Wi-Fi signals toward hard-to-reach areas. Seamlessly connect phones, TVs, and gaming consoles.
OWASP’s Input Validation Cheat Sheet says, “Input validation should happen as early as possible in the data flow, preferably as soon as the data is received from the external party.” Use validation to enforce what the application accepts; use the specific defense suited to the place that data is used.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.6. Use parameterized SQL
Do not build SQL by concatenating user input into a query. Prepare the statement separately and pass values as parameters so the database treats them as data:
$stmt = $pdo->prepare(
'SELECT id, name FROM users WHERE email = :email'
);
$stmt->execute(['email' => $email]);
$user = $stmt->fetch();
Parameter binding is for values, not arbitrary SQL syntax. If a query must sort by a user-selected column, map the request to a fixed allowlist of permitted column names and insert only the selected trusted identifier into the query. Do not accept a raw column name or sort expression from the request.
Give the application’s database account only the privileges it needs. Least privilege limits the consequences of a separate query-construction mistake.
Best Value
- Dual band router upgrades to 1200 Mbps high speed internet (300mbps for 2.4GHz plus 900Mbps for 5GHz), reducing buffering and ideal for 4K stream
- Full Gigabit Ports - Gigabit Router with 4 Gigabit LAN ports, ideal for any internet plan and allow you to directly connect your wired devices
- Boosted Coverage - Four external antennas equipped with Beamforming technology extend and concentrate the Wi-Fi signals
- MU-MIMO technology - (5GHz band) allows high speeds for multiple devices simultaneously
- Access Point Mode - Supports AP Mode to transform your wired connection into wireless network, an ideal wireless router for home
7. Protect state-changing requests and manage sessions safely
For every state-changing request, use the framework’s CSRF protection or a token that the server validates. This includes actions such as updating account details, making a purchase, or changing permissions. SameSite cookies can reduce some cross-site request risks, but they are defense in depth—not a general replacement for CSRF token validation.
Set cookie protections deliberately
Configure session cookies to be sent only over HTTPS and inaccessible to ordinary JavaScript, and choose a SameSite policy appropriate to the application’s flows. PHP configuration examples include:
session.use_only_cookies = 1
session.use_strict_mode = 1
session.cookie_secure = 1
session.cookie_httponly = 1
session.cookie_samesite = Lax
These are example settings, not a drop-in configuration for every app. Set them before starting the session, and choose cookie scope, lifetime, and SameSite behavior to fit the deployment. Test any sign-in or cross-site integration flows affected by the policy.
Control the session lifecycle
- Regenerate the session identifier after authentication and privilege changes.
- Keep the authenticated session on HTTPS for its entire lifetime.
- Invalidate the server-side session when the user logs out.
- Never put session identifiers in URLs, where they can leak through browser history, logs, or referrers.
8. Log security events and configure response headers carefully
Useful security logs can help detect and investigate problems. Record events such as authentication outcomes, authorization failures, and session-management failures, with enough context to understand what happened. Protect log access and retention, and exclude passwords, raw session IDs, and other secrets. Logs that expose credentials or tokens create a second route to account compromise.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Deploy security headers with care
- HTTP Strict Transport Security (HSTS): Enable it only after HTTPS works across the domain and any subdomains covered by the policy. A long-lived policy can make a misconfigured covered site unreachable until the policy expires.
- Content Security Policy (CSP): A carefully tailored policy can help mitigate some XSS and data-injection attacks. Because it can also block scripts a site relies on, test it against the application’s actual pages and script sources before enforcing it.
Review security controls in code as well as configuration. OWASP’s secure-code-review guidance highlights areas such as input handling, query construction, authentication, authorization, data flows, trust boundaries, and dependencies—useful places to focus a review without assuming that any single tool or header can secure the application by itself.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

