spatie/laravel-csp
Add Content Security Policy (CSP) headers to your Laravel app with easy configuration and preset policies. Control which scripts, styles, images, and connections are allowed, reduce XSS/data exfiltration risk, and support reporting and nonces.
|
Package
|
Score
|
Description
|
Stars
|
Likes
|
Forks
|
Downloads
|
Issues
|
Score
|
Opportunity
|
License
|
Last Release
|
|
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| bepsvpt/secure-headers | 0.83 | — | 549 | 551 | 47 | 139K | 2 | 4.6 | 33.2 | MIT | — | |
| spatie/boost-spatie-guidelines | 0.82 | AI-optimized Spatie coding guidelines for Laravel Boost. Installs battle-tested Laravel & PHP standards into your .ai/guidelines folder so AI assistants generate PSR-compliant, convention-driven code (types, naming, control flow, testing) automatically. | 105 | 103 | 3 | 39K | 0 | 16.5 | 40.2 | MIT | 2 months ago | |
| spatie/guidelines-skills | 0.82 | Spatie’s battle-tested coding guidelines packaged as AI skills for Laravel Boost and skills.sh. Includes Laravel/PHP, JavaScript, version control, and security conventions. Install via Composer/Boost or npx and keep updated easily. | 86 | 75 | 3 | 7K | 0 | 19.1 | 30.2 | MIT | 1 month ago | |
| paragonie/csp-builder | 0.82 | Build and send Content-Security-Policy headers in PHP from JSON files, JSON strings, or arrays. CSP Builder makes it easy to define directives programmatically and integrate CSP into web apps to improve security. | 541 | 545 | 39 | 80K | 7 | 13.6 | 31.7 | MIT | 1 year ago | |
| spatie/laravel-cors | 0.82 | Adds configurable CORS support to Laravel/Lumen: sets CORS headers on responses, handles preflight requests, and lets you define allowed origins, methods, headers, and credentials via middleware and config. Abandoned since Laravel 7+ has native CORS support. | 597 | 613 | 56 | 5K | 0 | 6.2 | 9.4 | MIT | 4 years ago | |
| aubes/csp-bundle | 0.81 | — | 2 | 2 | 0 | 19 | 0 | 18.6 | 13.8 | MIT | 1 month ago | |
| make-dev/laravel-security | 0.81 | Drop-in security headers for Laravel 11–13: HSTS, CSP with per-request nonces and strict-dynamic, X-Content-Type-Options, Permissions-Policy, and Subresource Integrity. Includes CSP/SRI violation report endpoints, logging/db storage, and Vapor-friendly SRI manifests. | 1 | 0 | 0 | 24 | 0 | 19.3 | 16.1 | MIT | 1 month ago | |
| spatie/laravel-responsecache | 0.77 | Cache full Laravel responses to speed up your app. Automatically caches successful text-based GET requests (HTML/JSON), with easy middleware per route, configurable lifetimes, and optional stale-while-revalidate “grace” caching to refresh in the background. | 2,797 | 2,821 | 245 | 260K | 0 | 51.1 | 31.9 | MIT | 1 week ago | |
| artisanpack-ui/security | 0.76 | artisanpack-ui/security adds security-focused UI components and helpers for Laravel ArtisanPack dashboards. Quickly integrate common protections and secure admin interfaces with minimal setup, offering sensible defaults and easy customization. | 0 | 0 | 1 | 186 | 6 | 23.1 | 38.4 | MIT | 2 weeks ago | |
| spatie/laravel-route-attributes | 0.72 | Register Laravel routes using PHP 8 attributes on controller methods (Get/Post/etc.). Automatically scans configured controller directories and registers routes without manual Route:: definitions. Includes config publishing and optional enabling/disabling of auto registration. | 886 | 890 | 86 | 59K | 0 | 31.0 | 28.6 | MIT | 2 months ago |
How can I help you explore Laravel packages today?