Security hardening for web projects
Security hardening protects websites and web apps from common attacks and keeps them up to date after launch.
Background
Most attacks exploit known gaps: unchecked input, outdated packages and weak admin log-ins. Many are automated and hit every site they can reach. The consequences range from downtime to data breaches that must be reported under the GDPR.
Protection in the code
SQL injection: prepared statements via the query builder and Eloquent
Cross-site scripting (XSS): context-aware escaping and a Content Security Policy
Cross-site request forgery (CSRF): tokens and session cookies set with SameSite, Secure and HttpOnly
Input and uploads: server-side validation, with files stored outside the public folder
Admin access and permissions
A second factor protects log-ins to the CMS and servers, and rate limiting slows down brute-force attempts. A role model grants only the rights each person needs. We remove old accounts regularly.
Servers and delivery
TLS with HSTS and security headers such as Permissions-Policy
Credentials in environment variables, never in the repository
Separate environments for development, staging and production
Encrypted backups, with restores tested regularly
Approach
We start with an audit based on the OWASP Top 10, with fixes rated by risk and effort. Once the site is live, automated scans check dependencies and we install security updates promptly.
For PlanetHome, we built a customer area with two-factor log-in to the guidelines of Germany's Federal Office for Information Security (BSI). It has passed several penetration tests.