make-dev/laravel-security
Drop-in security headers for Laravel 11–13: HSTS, CSP with per-request nonces and strict-dynamic, X-Content-Type-Options, Permissions-Policy, and Subresource Integrity. Includes CSP/SRI violation report endpoints, logging/db storage, and Vapor-friendly SRI manifests.
Adopt if:
Look elsewhere if:
spatie/laravel-csp for granularity).sri:warm workarounds).*"This package automates 80% of our web security compliance—HSTS, CSP, SRI—with zero dev time. It’s like a ‘firewall for your frontend’:
*"This is a drop-in security middleware that:
strict-dynamic (modern browsers).php artisan security:install for an interactive wizard that auto-configures GTM, HubSpot, etc.*"This eliminates manual CSP/SRI configuration—a top attack vector. Key benefits:
How can I help you explore Laravel packages today?