A threat model answers three questions: what can an attacker send you, what do you do with it, and what happens if it is hostile. The inputs are every superglobal in Requests and Forms ($_GET, $_POST, $_COOKIE, $_SERVER headers, $_FILES), plus anything read back from your own database (Subsection 4.17.4), a cache or an API. Treat all of it as attacker-controlled until validated or escaped for where it goes. The OWASP Top 10 is the shared list of what goes wrong; each risk below names the subsection that demonstrates it.
| OWASP 2025 risk | Where it bites PHP | Covered in |
|---|---|---|
| A01 Broken Access Control (incl. SSRF, CSRF) | missing checks, forged requests | 4.17.8, 4.17.14 |
| A02 Security Misconfiguration | verbose errors, open dirs, expose_php | 4.17.17, 4.13.7 |
| A03 Software Supply Chain Failures | outdated or malicious packages | 4.17.1, 4.12.7 |
| A04 Cryptographic Failures | weak hashing, home-made crypto | 4.17.9-4.17.12 |
| A05 Injection (SQL, XSS, command) | strings pasted into an interpreter | 4.17.2-4.17.6, 4.17.15 |
| A06 Insecure Design | no rate limit, guessable IDs | 4.17.16 |
| A07 Authentication Failures | weak passwords, session fixation | 4.17.9, 4.17.16 |
| A08 Software or Data Integrity Failures | unserialize() of user input | 4.17.4 |
| A09 Logging and Alerting Failures | nothing recorded, nothing noticed | 4.13.14 |
| A10 Mishandling of Exceptional Conditions | errors that leak or fail open | 4.13 |
Two 2025 categories are newer: SSRF is now folded into A01, and A03 broadened "vulnerable components" into the whole software supply chain, which for PHP means Composer 5,243 . composer audit reports any dependency with a published advisory, exiting non-zero so a CI pipeline fails. Over a lock still pinning an old guzzlehttp/psr7 it reports:
Found 5 security vulnerability advisories affecting 1 package: Package: guzzlehttp/psr7 CVE: CVE-2026-59882 Title: guzzlehttp/psr7: Host Confusion via Weak URI Host Validation ... exit=1
Composer 2.9+ also refuses by default to add an advisory-affected version (policy.advisories.block); for a stronger guarantee, add roave/security-advisories 2,918 (https://github.com/Roave/SecurityAdvisories 2,918 ) as a dev dependency, whose conflict rules make composer update reject them outright. Subsection 4.12.7 covers the workflow.