zappzarapp/security 问题修复 & 功能扩展

解决BUG、新增功能、兼容多环境部署,快速响应你的开发需求

邮箱:yvsm@zunyunkeji.com | QQ:316430983 | 微信:yvsm316

zappzarapp/security

Composer 安装命令:

composer require zappzarapp/security

包简介

Comprehensive PHP security library: CSP, Security Headers, CSRF, Cookies, Password Validation, Input Sanitization, Rate Limiting, SRI, and Audit Logging

README 文档

README

Latest Version PHP Version License CI Socket Badge

Comprehensive PHP security library providing CSP, Security Headers, CSRF protection, Secure Cookies, Password Validation, Input Sanitization, Rate Limiting, SRI, and Audit Logging.

Highlights

  • All-in-one — 11 security modules in a single, composable package
  • Secure by default — strict CSP, no unsafe-*, HTTPS-first
  • Framework-agnostic — works with any PHP 8.4+ application
  • Immutable & type-safe — readonly classes, enums, with*() API
  • Quality-backed — PHPStan Level 8, Psalm Level 1, 100% Mutation Score, Deptrac architecture enforcement
  • PSR-compatible — PSR-3 (Logging), PSR-15 (Middleware), PSR-18 (HTTP Client)

Modules

Module Description Key Classes
CSP Content Security Policy header building CspDirectives, HeaderBuilder, NonceGenerator
Headers Security headers (HSTS, Permissions-Policy, etc.) SecurityHeaders, SecurityHeadersBuilder
CSRF Cross-Site Request Forgery protection CsrfProtection, CsrfConfig
Cookie Secure cookie handling SecureCookie, CookieBuilder, CookieOptions
Password Password validation and hashing PasswordPolicy, PwnedPasswordChecker, PepperedPasswordHasher
Sanitization Input sanitization (HTML, SQL, URI, Path) HtmlSanitizer, UriSanitizer, PathValidator
RateLimiting Rate limiting with multiple algorithms DefaultRateLimiter, RateLimitConfig
SRI Subresource Integrity hash generation SriHashGenerator, IntegrityAttribute
Analyzer Security header analysis and auditing SecurityHeaderAnalyzer, AnalysisResult
Middleware PSR-15 middleware for drop-in framework integration SecurityHeadersMiddleware, CspMiddleware, CsrfMiddleware, DoubleSubmitCsrfMiddleware, RateLimitMiddleware, CorsMiddleware
Logging Security event audit logging SecurityAuditLogger, SecurityEvent

Requirements

  • PHP ^8.4
  • ext-dom
  • ext-libxml
  • ext-sodium

Installation

composer require zappzarapp/security

Quick Start

Security Headers

use Zappzarapp\Security\Headers\Builder\SecurityHeadersBuilder;

$headers = SecurityHeadersBuilder::recommended()->build();
foreach ($headers as $name => $value) {
    header("{$name}: {$value}");
}

CSP with Nonces

use Zappzarapp\Security\Csp\HeaderBuilder;
use Zappzarapp\Security\Csp\Directive\CspDirectives;
use Zappzarapp\Security\Csp\Nonce\NonceGenerator;

$generator = new NonceGenerator();
$csp = HeaderBuilder::build(CspDirectives::strict(), $generator);
header("Content-Security-Policy: {$csp}");

$nonce = $generator->get();
echo "<script nonce=\"{$nonce}\">console.log('Safe!');</script>";

CSRF Protection

use Zappzarapp\Security\Csrf\CsrfProtection;
use Zappzarapp\Security\Csrf\Storage\SessionCsrfStorage;

$csrf = new CsrfProtection(new SessionCsrfStorage());

// Generate token for form
$token = $csrf->generateToken();
echo '<input type="hidden" name="_token" value="' . $token->value() . '">';

// Validate on submission
if (!$csrf->validateToken($_POST['_token'])) {
    throw new Exception('CSRF validation failed');
}

Input Sanitization

use Zappzarapp\Security\Sanitization\Html\HtmlSanitizer;
use Zappzarapp\Security\Sanitization\Path\PathValidator;

// Sanitize HTML (removes dangerous tags/attributes)
$sanitizer = new HtmlSanitizer();
$safe = $sanitizer->sanitize($userInput);

// Validate file paths (prevent directory traversal)
$validator = new PathValidator('/var/www/uploads');
if (!$validator->isValid($userPath)) {
    throw new Exception('Invalid path');
}

See the documentation for detailed examples of all modules.

Documentation

Each module has detailed API documentation with class references, configuration options, and code examples:

Module Description
CSP Content Security Policy with nonces
Headers HSTS, COOP, COEP, CORP, Permissions
CSRF Token patterns and validation
Cookie Secure cookie handling
Password Hashing, policies, breach detection
Sanitization HTML, URI, path sanitization
Rate Limiting Token bucket, sliding window
SRI Subresource integrity hashes
Analyzer Security header auditing
Middleware PSR-15 middleware
Logging Security audit logging
Glossary Security terminology reference

Versioning

This library follows Semantic Versioning 2.0.0.

All classes, interfaces, and methods in the Zappzarapp\Security namespace are considered public API unless marked with @internal. Breaking changes only happen in major versions, with deprecation warnings at least one minor version before removal.

Releases are automated via release-please and GPG-signed. See CHANGELOG.md for release history.

Security

See SECURITY.md for vulnerability reporting and security considerations.

Contributing

See CONTRIBUTING.md for development setup and contribution guidelines.

License

MIT License - see LICENSE file for details.

zappzarapp/security 适用场景与选型建议

zappzarapp/security 是一款 基于 PHP 开发的 Composer 扩展包,目前已累计 12 次下载、GitHub Stars 达 0, 最近一次更新时间为 2026 年 02 月 12 日, 在 PHP 生态内属于活跃度较高的组件。

它主要适用于以下技术方向: 「security」 「cors」 「password」 「headers」 「csrf」 「xss」 等业务场景。在实际项目中,围绕这些方向常见需要落地的问题包括:接口对接、性能调优、并发安全、与既有框架(Laravel / ThinkPHP / Yii / Webman 等)的兼容适配,以及生产环境的日志埋点与稳定性保障。

我们在过去多个企业项目中使用过 zappzarapp/security 或与其功能相近的方案,如果你在选型或落地过程中遇到问题,例如 版本兼容、二次改造、私有化封装、与内部系统对接、生产 BUG 排查,欢迎联系我们协助评估。

围绕 zappzarapp/security 我们能提供哪些服务?
定制开发 / 二次开发

基于 zappzarapp/security 在你已有业务上做功能扩展、字段裁剪、UI 适配、与内部账号 / 权限 / 日志系统的深度对接。

BUG 修复 & 性能优化

线上偶发问题、内存泄漏、慢查询、并发异常等排查修复;针对高流量场景做缓存、队列、索引层面的调优。

项目外包 & 长期维护

承接完整的项目从需求 → 设计 → 开发 → 上线 → 长期运维;也可按月提供技术保姆服务。

yvsm@zunyunkeji.com QQ:316430983 微信:yvsm316 西安尊云信息科技 · 专注 PHP / Go / 分布式系统研发

统计信息

  • 总下载量: 12
  • 月度下载量: 0
  • 日度下载量: 0
  • 收藏数: 0
  • 点击次数: 63
  • 依赖项目数: 0
  • 推荐数: 0

GitHub 信息

  • Stars: 0
  • Watchers: 0
  • Forks: 0
  • 开发语言: PHP

其他信息

  • 授权协议: MIT
  • 更新时间: 2026-02-12