Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
zappzarapp-php-security — PHP 8.4+ security library (mirror) | Kitploit
Tools/GitLabGitLab/marcstraube/zappzarapp-php-security
Authentication & AuthorizationEncryption/Decryption ToolsVulnerability AnalysisCode AnalysisConfiguration AuditingWeb SecurityDevSecOpsAPI SecurityLog Analysis
GitLabmarcstraube/zappzarapp-php-security

zappzarapp-php-security

PHP 8.4+ security library (mirror)

1427 days agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
View Repository

⚡ zappzarapp/security

Latest Version PHP Version License CI Socket Badge

Comprehensive PHP security library providing CSP, Security Headers, CSRF protection, Secure Cookies, Password Validation, Input Sanitization, Rate Limiting, SRI, Secrets Loading, Encryption, Session Security, TOTP two-factor authentication, Signed URLs, and Security Event Logging.

Highlights

  • All-in-one — 17 security modules in a single, composable package
  • Secure by default — strict CSP, no unsafe-*, HTTPS-first
  • Framework-agnostic — works with any PHP 8.4+ application
  • Immutable & type-safe — readonly classes, enums, with*() API
  • Quality-backed — PHPStan Level 8, Psalm Level 1, 100% Mutation Score, Deptrac architecture enforcement
  • PSR-compatible — PSR-3 (Logging), PSR-15 (Middleware), PSR-18 (HTTP Client)

Modules

ModuleDescriptionKey Classes
CSPContent Security Policy header building and violation reportingCspDirectives, HeaderBuilder, NonceGenerator, CspReportParser
HeadersSecurity headers (HSTS, Permissions-Policy, etc.)SecurityHeaders, SecurityHeadersBuilder
CSRFCross-Site Request Forgery protectionCsrfProtection, CsrfConfig
CookieSecure cookie handlingSecureCookie, CookieBuilder, CookieOptions
EncryptionXChaCha20-Poly1305 authenticated encryptionSymmetricEncryptor, EnvelopeEncryptor, EncryptionKey, KeyRingEncryptor
PasswordPassword validation and hashingPasswordPolicy, PwnedPasswordChecker, PepperedPasswordHasher
SanitizationInput sanitization (HTML, SQL, URI, Path) and file upload validationHtmlSanitizer, UriSanitizer, PathValidator, UploadValidator
RateLimitingRate limiting with multiple algorithmsDefaultRateLimiter, RateLimitConfig
SRISubresource Integrity hash generationSriHashGenerator, IntegrityAttribute
SecretsDocker/file-based secret loadingSecretLoader, SecretValue, FileSecretSource
SessionSession hardening and fixation protectionSessionGuard, SessionConfig, SessionConfigurator
SignedUrlHMAC-signed URLs with mandatory expiryUrlSigner, SigningKey
TOTPTime-based one-time passwords (RFC 6238)TotpAuthenticator, TotpSecret, ProvisioningUri, RecoveryCodeGenerator
AnalyzerSecurity header analysis and auditingSecurityHeaderAnalyzer, AnalysisResult
ScannerCLI security header scannerScanCommand, StreamHeaderFetcher
MiddlewarePSR-15 middleware for drop-in framework integrationSecurityHeadersMiddleware, CspMiddleware, CspReportHandler, CsrfMiddleware, DoubleSubmitCsrfMiddleware, RateLimitMiddleware, CorsMiddleware
LoggingSecurity event loggingSecurityAuditLogger, SecurityEvent

Requirements

  • PHP ^8.4
  • ext-dom
  • ext-libxml
  • ext-sodium

Installation

composer require zappzarapp/security

Quick Start

Security Headers

use Zappzarapp\Security\Headers\Builder\SecurityHeadersBuilder;

$headers = SecurityHeadersBuilder::recommended()->build();
foreach ($headers as $name => $value) {
    header("{$name}: {$value}");
}

CSP with Nonces

use Zappzarapp\Security\Csp\HeaderBuilder;
use Zappzarapp\Security\Csp\Directive\CspDirectives;
use Zappzarapp\Security\Csp\Nonce\NonceGenerator;

$generator = new NonceGenerator();
$csp = HeaderBuilder::build(CspDirectives::strict(), $generator);
header("Content-Security-Policy: {$csp}");

$nonce = $generator->get();
echo "<script nonce=\"{$nonce}\">console.log('Safe!');</script>";

CSRF Protection

use Zappzarapp\Security\Csrf\CsrfProtection;
use Zappzarapp\Security\Csrf\Storage\SessionCsrfStorage;

$csrf = new CsrfProtection(new SessionCsrfStorage());

// Generate token for form
$token = $csrf->generateToken();
echo '<input type="hidden" name="_token" value="' . $token->value() . '">';

// Validate on submission
if (!$csrf->validateToken($_POST['_token'])) {
    throw new Exception('CSRF validation failed');
}

Input Sanitization

use Zappzarapp\Security\Sanitization\Html\HtmlSanitizer;
use Zappzarapp\Security\Sanitization\Path\PathValidationConfig;
use Zappzarapp\Security\Sanitization\Path\PathValidator;

// Sanitize HTML (removes dangerous tags/attributes)
$sanitizer = new HtmlSanitizer();
$safe = $sanitizer->sanitize($userInput);
Download Tool