OWASP Top 10 for the Lazy PHP Developer

Talk • PHP • Security • OWASP

The talk that should have been at https://www.gunnard.org/talks/owasp-top-10-lazy-php.pdf — now also as a readable page.

Slides: Download PDF

Abstract

Most PHP security talks shame you for not hand-rolling perfect crypto. This one assumes you’re lazy — you want the least work that still keeps you out of the breach headlines.

We walk the OWASP Top 10 through real, boring PHP code: the app you actually ship (mysqli, sessions, file uploads, old Symfony/Laravel, or no framework at all). For each item: what the attack looks like, the one-line fix, and the habit that prevents the next one.

No FUD, no compliance theater. Just: here’s the bug, here’s the diff, here’s how to not do it again.

What you’ll take away

  • Why injection is still #1 in PHP (and the 2 prepared-statement patterns that kill it)
  • Auth/session bugs that survive password_hash() — and what to check in 5 minutes
  • XSS without React — escaping where it actually matters in legacy templates
  • A 30-minute checklist you can run on any PHP codebase next Monday

Resources

Reported 404 fixed 2026-09-17 — thanks to Barbara Fletcher for the heads-up.