Skip to content

Security hardening for web projects

Security hardening protects websites and web apps from common attacks and keeps them up to date after launch.

Background

Most attacks exploit known gaps: unchecked input, outdated packages and weak admin log-ins. Many are automated and hit every site they can reach. The consequences range from downtime to data breaches that must be reported under the GDPR.

Protection in the code

  • SQL injection: prepared statements via the query builder and Eloquent

  • Cross-site scripting (XSS): context-aware escaping and a Content Security Policy

  • Cross-site request forgery (CSRF): tokens and session cookies set with SameSite, Secure and HttpOnly

  • Input and uploads: server-side validation, with files stored outside the public folder

Admin access and permissions

A second factor protects log-ins to the CMS and servers, and rate limiting slows down brute-force attempts. A role model grants only the rights each person needs. We remove old accounts regularly.

Servers and delivery

  • TLS with HSTS and security headers such as Permissions-Policy

  • Credentials in environment variables, never in the repository

  • Separate environments for development, staging and production

  • Encrypted backups, with restores tested regularly

Approach

We start with an audit based on the OWASP Top 10, with fixes rated by risk and effort. Once the site is live, automated scans check dependencies and we install security updates promptly.

For PlanetHome, we built a customer area with two-factor log-in to the guidelines of Germany's Federal Office for Information Security (BSI). It has passed several penetration tests.

Project enquiry

Back to top