Stephen Rees-Carter @valorin.bsky.social · 27/09/2026Not a bad view to write a new In Depth article. 😎 I'm doing a walkthrough of the results from Claude's security plugin on one of my projects, looking at the quality of the findings and how we can identify the real risks from the noise. 160
Stephen Rees-Carter @valorin.bsky.social · 18/09/2026How does everyone feel about pentest findings/reports available online (behind auth), as opposed to emailed or sent via Slack/Teams? I've always been wary of putting them online, even behind auth, but I can see some benefits - especially with agents doing the remediation work. 010
Stephen Rees-Carter @valorin.bsky.social · 07/09/2026During a recent pentest, I suddenly got hit with 403s on every request. It wasn't a WAF - it was a clever little trap one of my clients built to catch anyone poking at Livewire. Let me show you how it works. 🤓 securinglaravel.com/security-tip... #Laravelsecuringlaravel.comSecurity Tip: The Trap That Caught Me![Security Tip #135] During a recent pentest, I suddenly got hit with 403s on every request. It wasn't a WAF - it was a clever little trap one of my clients built to catch anyone poking at Livewire.… 172
Stephen Rees-Carter @valorin.bsky.social · 02/09/2026Just scheduled my next Security Tip. Feels nice to be scheduling them in advance again, rather than posting late! 😎 This is a rather fun one too: a story from a recent pentest where the client's defences caught me! 160
Reposted by Stephen Rees-CarterAndrew Feeney @andrewfeeney.au · 31/08/2026How can you level up as a PHP / Laravel focused web developer in a world where software engineering becomes increasingly focused on security? Step 1: Sign up to @valorin.bsky.social's Securing Laravel newsletter. Congrats on an epic 5 years Stephen! Still some of the best content on the topic. 151
Stephen Rees-Carter @valorin.bsky.social · 31/08/2026 Yikes! I've been writing Securing Laravel for 5 years! 😲 securinglaravel.com/5-years-of-s... #Laravelsecuringlaravel.com5 years of Securing Laravel!Yikes! I've been writing Securing Laravel for 5 years! 😲 160
Stephen Rees-Carter @valorin.bsky.social · 31/08/2026Laravel's password helper has a great little feature you may have missed: it can generate browser-friendly password rules automatically! 🤓 securinglaravel.com/security-tip... #Laravelsecuringlaravel.comSecurity Tip: Help Password Managers Get It Right![Tip #134] Laravel's password helper has a great little feature you may have missed: it can generate browser-friendly password rules automatically! 🤓 061
Stephen Rees-Carter @valorin.bsky.social · 24/08/2026I've been struggling with mental and physical health issues for the past few years, and one of the things that really helped this year was finding a hobby away from technology where I get to work with my hands. Here's what I've been doing: pottery.valorin.netpottery.valorin.netGallery - Pottery by StephenHandmade pottery by Stephen — every piece thrown, glazed & fired by hand. 4121
Stephen Rees-Carter @valorin.bsky.social · 21/08/2026unserialize() looks harmless - it just rebuilds your data - but feed it the wrong string and it'll rebuild an attacker's object, quietly turning Laravel's own code into remote code execution. Let's pull a real RCE apart. 😈 securinglaravel.com/in-depth-fro... #Laravelsecuringlaravel.comIn Depth: From Serialised String to RCE![In Depth #41] unserialize() looks harmless - it just rebuilds your data - but feed it the wrong string and it'll rebuild an attacker's object, quietly turning Laravel's own code into remote code… 071
Stephen Rees-Carter @valorin.bsky.social · 13/08/2026Submitted my first CVEs directly to MITRE due to an unresponsive package maintainer for a very popular package that sits at #5 for a common search term on Packagist. Will be interesting to see how this goes. 060
Stephen Rees-Carter @valorin.bsky.social · 06/08/2026Um... that's not how risks work... 🤦 This is the rubbish being peddled by big companies selling "Cyber Insurance". 😡 140
Stephen Rees-Carter @valorin.bsky.social · 06/08/2026One of the most satisfying (and most frustrating!) parts of pentesting is spending an hour setting up the perfect PoC, composing shock-value screenshots, and writing a succinct report - only for them to spend 30 seconds making a trivial code change that fixes the issue. 😈😱 050
Stephen Rees-Carter @valorin.bsky.social · 03/08/2026SameSite=Lax is the Laravel default, and it quietly protects you from CSRF. So why do I keep finding SameSite=None in the apps I audit? Let's talk about what it does and how to use it safely. securinglaravel.com/security-tip... #Laravelsecuringlaravel.comSecurity Tip: Do You Know Your SameSite Cookies?[Tip #133] SameSite=Lax is the Laravel default, and it quietly protects you from CSRF. So why do I keep finding SameSite=None in the apps I audit? Let's talk about what it does and how to use it… 050
Reposted by Stephen Rees-CarterRed Pill Junkie @redpilljunkie.bsky.social · 22/07/2026Elon demanding a 'historically accurate' Odyssey is like a child demanding a historically accurate Smurfs movie. 1168
Stephen Rees-Carter @valorin.bsky.social · 23/07/2026Received some great feedback from a client recently, and it really highlights why I specialise in PHP & Laravel as a pentester: "The fact that you understand both security *and* the frameworks I’m building with is such a big advantage over other firms that I’ve worked with." 🥰 040
Stephen Rees-Carter @valorin.bsky.social · 20/07/2026What do you get when you combine an API, SameSite=None, and a Session cookie? securinglaravel.com/in-depth-thr... #Laravelsecuringlaravel.comIn Depth: Three Reasonable Decisions, One Critical Vulnerability[In Depth #41] What do you get when you combine an API, SameSite=None, and a Session cookie? 011
Stephen Rees-Carter @valorin.bsky.social · 10/07/2026Working on a fun In Depth article for Securing Laravel at the moment. 😈 The tagline is: What do you get when you combine an API, SameSite=None, and a Session cookie? Any guesses? 110
Stephen Rees-Carter @valorin.bsky.social · 02/07/2026Your AI agent hallucinates a package name, confidently installs it, and keeps working - except an attacker registered that exact name, packed with malware. Welcome to slopsquatting. securinglaravel.com/security-tip... #Laravelsecuringlaravel.comSecurity Tip: Have You Heard Of Slopsquatting?[Tip #132] Your AI agent hallucinates a package name, confidently installs it, and keeps working - except an attacker registered that exact name, packed with malware. Welcome to slopsquatting. 041
Stephen Rees-Carter @valorin.bsky.social · 01/07/2026Recently finished an audit for one of my oldest clients, this was #5! 🕵️ By far the most rewarding part of my job is working with the same clients each year, seeing their apps grow, and their commitment to security strengthen. It's not just a compliance checkbox, it's part of their culture.valorinsecurity.comLaravel Security Audits and Penetration Tests – Stephen Rees-CarterLooking for a Laravel Security Audit and Pentest? I'm Stephen Rees-Carter and I'm excited to work with you to secure your site, and keep it safe! 110
Stephen Rees-Carter @valorin.bsky.social · 22/06/2026Updating packages used to be a no-brainer, but now you need to be careful. Updates may be malicious. But not updating leaves vulns unpatched. So what do you do??? 🤷 securinglaravel.com/security-tip... #Laravelsecuringlaravel.comSecurity Tip: Safely Updating Dependencies[Tip #131] Updating packages used to be a no-brainer, but now you need to be careful. Updates may be malicious. But not updating leaves vulns unpatched. So what do you do??? 🤷 040
Stephen Rees-Carter @valorin.bsky.social · 15/06/2026Things Claude says... > Is that concerning? For local files it's not a vuln — it's theater > Is it TOFU? No — weaker than TOFU Ouch. 110
Stephen Rees-Carter @valorin.bsky.social · 11/06/2026Nobody cares about security until they suddenly care about nothing else... A breach, a near miss, an awkward client question, and it's suddenly top priority! Get ahead. I do Laravel Security Audits & Pentests, ideally on a quiet day, not the worst one. 🕵️ valorinsecurity.comvalorinsecurity.comLaravel Security Audits and Penetration Tests – Stephen Rees-CarterLooking for a Laravel Security Audit and Pentest? I'm Stephen Rees-Carter and I'm excited to work with you to secure your site, and keep it safe! 031
Stephen Rees-Carter @valorin.bsky.social · 08/06/2026We trust version numbers to mean a specific, fixed release - but they're really just labels pointing at a commit, and an attacker can quietly move them. Let's dig into tag hijacking, the attack behind tj-actions and Laravel-Lang. 😈 securinglaravel.com/in-depth-ver... #Laravelsecuringlaravel.comIn Depth: Version Numbers Are Vanity Labels[In Depth # 40] We trust version numbers to mean a specific, fixed release - but they're really just labels pointing at a commit, and an attacker can quietly move them. Let's dig into tag hijacking,… 030
Stephen Rees-Carter @valorin.bsky.social · 04/06/2026If you've been shipping AI-written Laravel code lately (and let's be honest, you probably have), it's worth getting a human to actually read it! Reach out for an Audit/Pentest for the parts of your codebase that vibed a little too hard. 🕵️ valorinsecurity.comvalorinsecurity.comLaravel Security Audits and Penetration Tests – Stephen Rees-CarterLooking for a Laravel Security Audit and Pentest? I'm Stephen Rees-Carter and I'm excited to work with you to secure your site, and keep it safe! 011
Stephen Rees-Carter @valorin.bsky.social · 01/06/2026I've got some capacity opening up over the next few months, so If you've been meaning to get a security audit / pentest done on your Laravel app - now is the time! 🕵️ 👉 DM or valorinsecurity.comvalorinsecurity.comLaravel Security Audits and Penetration Tests – Stephen Rees-CarterLooking for a Laravel Security Audit and Pentest? I'm Stephen Rees-Carter and I'm excited to work with you to secure your site, and keep it safe! 010
Stephen Rees-Carter @valorin.bsky.social · 01/06/2026With Supply Chain Attacks, you often don't realise you've been compromised until it's already too late. And yet Canary Tokens - exactly the early warning you want - are hardly mentioned. They let you know the moment someone's sniffing around. securinglaravel.com/security-tip...securinglaravel.comSecurity Tip: Canary Tokens[Tip#31] These are my favourite simple security trick to let you know if someone is poking around in your stuff. 072
Stephen Rees-Carter @valorin.bsky.social · 29/05/2026I may have gone to Japan and spent more time looking for these than sightseeing... maybe... (Technically I went sightseeing while looking for these, so it counts as sightseeing time, right?) 010
Reposted by Stephen Rees-CarterJordi Boggiano @seld.be · 28/05/2026📦 Composer 2.10 is out. Native malware filtering via @aikidosecurity.bsky.social (enabled by default on Packagist), a unified config.policy framework for advisories/abandoned/malware, and source fallback now deprecated. blog.packagist.com/composer-2-1... #php #phpc #composerphpblog.packagist.comComposer 2.10 ReleaseWe are excited to announce the release of Composer 2.10.0, introducing native malware filtering and consolidated future-proof customizable dependency policy configuration to control the handling of se... 01710
Reposted by Stephen Rees-CarterDaniel Newns @dannewns.bsky.social · 26/05/2026It's apt then that in my inbox today is a email from @valorin.bsky.social with his latest security tip - securinglaravel.com/security-tip... and then the release of Laravel Moat by @nunomaduro.com - laravel.com/blog/moat-a-...securinglaravel.comSecurity Tip: Secure Your Repositories with Laravel Moat[Tip #130] Laravel Moat is a new tool that assesses the security posture of your GitHub repositories and recommends ways to tighten the controls protecting them. 122
Stephen Rees-Carter @valorin.bsky.social · 26/05/2026Laravel Moat is a new tool that assesses the security posture of your GitHub repositories and recommends ways to tighten the controls protecting them. github.com/laravel/moat securinglaravel.com/security-tip... #Laravelgithub.comGitHub - laravel/moat: Moat reviews the security posture of your GitHub organization and repositories, then surfaces recommendations to consider.Moat reviews the security posture of your GitHub organization and repositories, then surfaces recommendations to consider. - laravel/moat 171
Stephen Rees-Carter @valorin.bsky.social · 28/04/2026I love Signed URLs, but there is one very subtle trap you can accidentally fall into... securinglaravel.com/security-tip... #Laravelsecuringlaravel.comSecurity Tip: The Signed URL Trap[Tip #129] I love Signed URLs, but there is one very subtle trap you can accidentally fall into... 181
Stephen Rees-Carter @valorin.bsky.social · 18/04/2026Livewire's Public Properties may look like PHP class properties, but they're really hidden form fields, just waiting for your input... 😈 securinglaravel.com/in-depth-don... #Laravelsecuringlaravel.comIn Depth: Don't Trust Public Livewire Properties[In Depth #39] Public Properties may look like PHP class properties, but they're really hidden form fields, just waiting for your input... 😈 193
Reposted by Stephen Rees-CarterMadeWithLaravel @madewithlaravel.com · 13/04/2026On the Securing Laravel blog, @valorin.bsky.social explores Laravel security concepts & techniques 🔐 - madewithlaravel.com/securing-lar... 011
Reposted by Stephen Rees-CarterChuck Wendig @chuckwendig.bsky.social · 13/04/2026Again, if you have a Substack, the best time to switch away was months ago -- but today's the second best time. 161563580
Stephen Rees-Carter @valorin.bsky.social · 18/03/2026Do you know the difference between GET and POST requests, and why it's so important that GET requests only ever retrieve data? securinglaravel.com/security-tip... #Laravelsecuringlaravel.comSecurity Tip: Stop Putting Actions on GET Requests![Tip #128] Do you know the difference between GET and POST requests, and why it's so important that GET requests only ever retrieve data? 080
Stephen Rees-Carter @valorin.bsky.social · 12/03/2026As Laravel's friendly hacker, I feel it is my duty to inform everyone that Laravel v11 is no longer supported! 😱 ❌ Bug fixes (they stopped 6 months ago) ❌ Security fixes (they stop today!) Have you upgraded yet? laravel.com/docs/release... #Laravellaravel.comRelease Notes | Laravel 12.x - The clean stack for Artisans and agentsLaravel is a PHP web application framework with expressive, elegant syntax. We’ve already laid the foundation — freeing you to create without sweating the small things. 074
Stephen Rees-Carter @valorin.bsky.social · 09/03/2026Without an `exp` claim, a JWT can remain valid forever, turning a leaked token into permanent access. securinglaravel.com/security-tip... #Laravelsecuringlaravel.comSecurity Tip: Your JWT Might Be a Forever Key![Tip #127] Without an `exp` claim, a JWT can remain valid forever, turning a leaked token into permanent access. 033
Stephen Rees-Carter @valorin.bsky.social · 02/03/2026Rather than checking for essential config when it's used, throw the checks in your Service Provider - you'll know about configuration failures before your users get a weird error. securinglaravel.com/security-tip... #Laravelsecuringlaravel.comSecurity Tip: Validate Config at Boot[Tip #126] Rather than checking for essential config when it's used, throw the checks in your Service Provider - you'll know about configuration failures before your users get a weird error. 050
Stephen Rees-Carter @valorin.bsky.social · 25/02/2026PSA for @statamic.com folks - update your sites ASAP! ⚠️ A CRITICAL vuln was discovered that allows full account takeover via password resets! 😱 All the details: cvereports.com/reports/CVE-...github.comCVE-2026-27593 - GitHub Advisory DatabaseStatamic is vulnerable to account takeover via password reset link injection 096
Stephen Rees-Carter @valorin.bsky.social · 24/02/2026I am determined to get back to @laravellive.dk this year, so if you have a dev team or a meetup in EU or UK and want me to run a workshop or give a talk in August, let me know! 010
Stephen Rees-Carter @valorin.bsky.social · 23/02/2026You can't trust an email address you haven't verified, so why are you storing them in your database? securinglaravel.com/in-depth-ema... #Laravelsecuringlaravel.comIn Depth: Email Verification Isn't as Simple as You Think[In Depth #38] You can't trust an email address you haven't verified, so why are you storing them in your database? 150
Stephen Rees-Carter @valorin.bsky.social · 14/02/2026routes/web.php is boring and reliable, and routes/api.php is fancy, but have you forgotten one? securinglaravel.com/security-tip...securinglaravel.comSecurity Tip: Consider All Routes, Not Just Web![Tip #125] routes/web.php is boring and reliable, and routes/api.php is fancy, but have you forgotten one? 061
Stephen Rees-Carter @valorin.bsky.social · 05/02/2026I know I say this all the time (especially on stage!), but apparently not everyone heard me, so here we go again... securinglaravel.com/security-tip...securinglaravel.com 021
Stephen Rees-Carter @valorin.bsky.social · 04/02/2026It's been 4 months, a lot has happened, but I'm finally back to writing securinglaravel.com! New Security Tip coming out in a few hours...securinglaravel.comSecuring LaravelThe essential security resource for Laravel developers. 090
Stephen Rees-Carter @valorin.bsky.social · 18/11/2025Exhausted after #LaraconAU last week, but excited by how it all went! I was so proud of everyone in my workshop on Wednesday - everyone had a go, and the excitement in the room as they hacked through challenges made it all worth it. 150
Stephen Rees-Carter @valorin.bsky.social · 17/10/2025Haven't bought tickets to my Pre-@laracon.au Security Workshop yet?! 😲 I'll be locking in numbers early next week, so get your ticket TODAY or reach out to me directly. ⌛ This is your final warning... ⏰ events.humanitix.com/lets-hack-pr...events.humanitix.com"Let's Hack!" Pre-Laracon Security WorkshopAttending Laracon AU? Come along to 001
Stephen Rees-Carter @valorin.bsky.social · 08/10/2025"Let's Hack!", my Pre-Laracon Security Workshop is just FIVE weeks away! 🎉 (So is @laracon.au... but let's be honest, priorities.) Only 11 tickets left, & I need to confirm numbers with the venue, so if you've been thinking about it, now's the time! 👉 events.humanitix.com/lets-hack-pr...events.humanitix.com"Let's Hack!" Pre-Laracon Security WorkshopAttending Laracon AU? Come along to 011
Stephen Rees-Carter @valorin.bsky.social · 29/09/2025If an API client tries to connect via unencrypted HTTP, what should your API do: redirect to HTTPS, disable HTTP, offer a swift rebuke, or take matters into it's own hands? 🤔 securinglaravel.com/security-tip... #Laravelsecuringlaravel.comSecurity Tip: How Should APIs Respond to HTTP?[Tip #123] If an API client tries to connect via unencrypted HTTP, what should your API do: redirect to HTTPS, disable HTTP, offer a swift rebuke, or take matters into it's own hands? 131
Stephen Rees-Carter @valorin.bsky.social · 25/09/2025Cookies come in many shapes and sizes, and with multiple attributes just to confuse you... Have you ever wondered what the humble HttpOnly attribute actually does? securinglaravel.com/security-tip... #Laravelsecuringlaravel.comSecurity Tip: What Is An HttpOnly Cookie?[Tip #86] Cookies come in many shapes and sizes, and with multiple attributes just to confuse you... Have you ever wondered what the humble HttpOnly attribute actually does? 160