pheromone/phpcs-security-audit
preg_replace('/e')).ParanoiaMode) in exchange for broad coverage.--parallel or --ignore).For Executives:
"This package plugs a critical gap in our security toolchain by automating PHP security audits—catching vulnerabilities like XSS, SQL injection, and RCE early in development. For example, it flagged 18 errors in a sample Drupal module, including direct user input in echo statements and dangerous preg_replace usage. By integrating this into CI/CD (e.g., Jenkins/GitHub Actions), we can fail builds on high-risk code, reducing breach risks and compliance audit friction. The cost? Minimal—it’s a lightweight PHP_CodeSniffer extension with a 700+ star open-source community. Tradeoff: Some false positives (tunable), but the alternative is manual reviews or costly breaches."
For Engineering: *"This is a PHP_CodeSniffer standard that adds security-specific sniffs (e.g., detecting unsafe functions, CVE patterns, or framework-specific risks like Drupal advisories). Key benefits:
composer require --dev pheromone/phpcs-security-audit).ParanoiaMode (0=lenient, 1=strict) or extend rules for your framework (e.g., override is_direct_user_input for custom CMS functions).--severity=5 for errors only).How can I help you explore Laravel packages today?