php-security
Installation
SKILL.md
PHP Security Best Practices
Input Validation
Validate at trust boundaries (controller/request layer). Use allowlist validation — define what is acceptable, reject everything else.
Validate with filter_var()
// ✅ SECURE — allowlist validation with filter_var
$email = filter_var($input['email'] ?? '', FILTER_VALIDATE_EMAIL);
if ($email === false) {
throw new \InvalidArgumentException('Invalid email');
}