duality-studio/lara-security

A straight implementation of security headers for Laravel
1,735
Install
composer require duality-studio/lara-security
Latest Version:v0.4.0
PHP:^8.2
License:MIT
Last Updated:Aug 29, 2026
Links: GitHub  ·  Packagist
Maintainer: thomaspalmer94

Lara Security

Simple way to add various security headers to a Laravel application.

This project is WIP and could with cleanup, better implementation and some docs.

Docs

TODO, the bellow is 5 minute notes.

Install

composer require duality-studio/lara-security

php artisan vendor:publish --provider="DualityStudio\LaraSecurity\LaraSecurityServiceProvider"

In your app/Http/Kernel.php add the following to the $middleware array or as you see fit.

\DualityStudio\LaraSecurity\SecurityHeaders::class,

In your config/lara-security.php you can configure the headers you want to use, all are enabled by default. In the CSP header is broken into directives.

Nonces

If you intend to use a nonce in your you will need to add a script or style directive for your static files.

<script @nonce(\DualityStudio\LaraSecurity\Directives::SCRIPT)>
    window.addEventListener('load', function () {
        console.log(1);
    });
</script>
<style @nonce(\DualityStudio\LaraSecurity\Directives::STYLE)>
    body {
        background: #fff;
    }
</style>

Usage with Vite

Set use_vite to true in the config file. This will automatically add the nonce to the script and style tags in the vite manifest.

Usage of the package is problematic when using the vite dev server, so you can disable the package when in dev mode by adding the following to your .env

LARA_SECURITY_ENABLED=false

Usage with Inertia.JS

If you are using Inertia.JS you will need to add the following to your app.blade.php file.

<!-- Scripts -->
@routes(null, nonce(\DualityStudio\LaraSecurity\Directives::SCRIPT))
@viteReactRefresh
@vite(['resources/js/app.jsx', "resources/js/Pages/{$page['component']}.jsx"])
@inertiaHead

Related Packages

offline/laravel-csp

Add CSP headers to the responses of a Laravel app (Fork)

5,533 1
spatie/laravel-csp

Add CSP headers to the responses of a Laravel app

13,103,538 873
infusionweb/laravel-middleware-response-cache

Provides caching of HTML pages in Laravel responses.

2,442 5
morilog/jalali

This Package helps developers to easily work with Jalali (Shamsi or Iranian) dat...

1,418,037 927
bepsvpt/secure-headers

Add security related headers to HTTP response. The package includes Service Prov...

5,710,011 550

Version History

Version Released PHP Laravel License
v0.4.0 ^8.2 ^9.0|^10.0|^11.0|^12.0|^13.0 MIT
v0.3.0 ^8.2 ^9.0|^10.0|^11.0|^12.0 MIT
v0.2.2 ^8.2 ^9.0|^10.0|^11.0 MIT
v0.2.1 ^8.2 ^9.0|^10.0|^11.0 MIT
v0.2 ^8.2 ^9.0|^10.0|^11.0 MIT