spatie/laravel-csp
Set Content Security Policy (CSP) headers in Laravel to control which scripts, styles, and resources can load and where they can send data. Helps prevent XSS and malicious third-party scripts. Includes report-only mode, nonces, and easy config.
|
Package
|
Score
|
Description
|
Stars
|
Likes
|
Forks
|
Downloads
|
Issues
|
Score
|
Opportunity
|
License
|
Last Release
|
|
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| bepsvpt/secure-headers | 0.84 | — | 550 | 552 | 48 | 157K | 2 | 4.6 | 33.8 | MIT | — | |
| artisanpack-ui/security | 0.83 | Core Laravel security toolkit for ArtisanPack UI: sanitization, escaping (Laminas Escaper), KSES filtering, validation rules, security/CSP middleware, CSP builder with nonce & reporting, rate limiting, audit/scan commands, and testing helpers. | 0 | 0 | 1 | 479 | 7 | 21.9 | 44.7 | MIT | 1 month ago | |
| paragonie/csp-builder | 0.83 | Build and send Content-Security-Policy headers in PHP from JSON files, JSON strings, or arrays. CSP Builder makes it easy to define directives programmatically and integrate CSP into web apps to improve security. | 541 | 546 | 39 | 84K | 7 | 13.8 | 32.7 | MIT | 1 year ago | |
| spatie/laravel-cors | 0.82 | Adds configurable CORS support to Laravel/Lumen: sets CORS headers on responses, handles preflight requests, and lets you define allowed origins, methods, headers, and credentials via middleware and config. Abandoned since Laravel 7+ has native CORS support. | 597 | 613 | 57 | 3K | 0 | 6.2 | 7.6 | MIT | 5 years ago | |
| aubes/csp-bundle | 0.82 | — | 2 | 2 | 0 | 4 | 0 | 16.2 | 5.8 | MIT | 3 months ago | |
| make-dev/laravel-security | 0.82 | Drop-in security headers for Laravel 11–13: HSTS, CSP with per-request nonces and strict-dynamic, X-Content-Type-Options, Permissions-Policy, and Subresource Integrity. Includes CSP/SRI violation report endpoints, logging/db storage, and Vapor-friendly SRI manifests. | 1 | 1 | 0 | 16 | 0 | 16.8 | 15.1 | MIT | 2 months ago | |
| spatie/boost-spatie-guidelines | 0.82 | AI-optimized Spatie coding guidelines for Laravel Boost. Installs battle-tested Laravel & PHP standards into your .ai/guidelines folder so AI assistants generate PSR-compliant, convention-driven code (types, naming, control flow, testing) automatically. | 106 | 106 | 3 | 38K | 0 | 14.5 | 39.3 | MIT | 4 months ago | |
| spatie/laravel-route-attributes | 0.72 | Register Laravel routes using PHP 8 attributes on controller methods (Get/Post/etc.). Automatically scans configured controller directories and registers routes without manual Route:: definitions. Includes config publishing and optional enabling/disabling of auto registration. | 888 | 894 | 87 | 53K | 0 | 28.7 | 27.3 | MIT | 4 months ago |
How can I help you explore Laravel packages today?