Threat Model

The Threat Model for a PHP Application

A threat model answers three questions: what can an attacker send you, what do you do with it, and what happens if it is hostile. The inputs are every superglobal in Requests and Forms ($_GET, $_POST, $_COOKIE, $_SERVER headers, $_FILES), plus anything read back from your own database (Subsection 4.17.4), a cache or an API. Treat all of it as attacker-controlled until validated or escaped for where it goes. The OWASP Top 10 is the shared list of what goes wrong; each risk below names the subsection that demonstrates it.

The OWASP Top 10 (2025) mapped onto this chapter
OWASP 2025 risk Where it bites PHP Covered in
A01 Broken Access Control (incl. SSRF, CSRF) missing checks, forged requests 4.17.8, 4.17.14
A02 Security Misconfiguration verbose errors, open dirs, expose_php 4.17.17, 4.13.7
A03 Software Supply Chain Failures outdated or malicious packages 4.17.1, 4.12.7
A04 Cryptographic Failures weak hashing, home-made crypto 4.17.9-4.17.12
A05 Injection (SQL, XSS, command) strings pasted into an interpreter 4.17.2-4.17.6, 4.17.15
A06 Insecure Design no rate limit, guessable IDs 4.17.16
A07 Authentication Failures weak passwords, session fixation 4.17.9, 4.17.16
A08 Software or Data Integrity Failures unserialize() of user input 4.17.4
A09 Logging and Alerting Failures nothing recorded, nothing noticed 4.13.14
A10 Mishandling of Exceptional Conditions errors that leak or fail open 4.13

Two 2025 categories are newer: SSRF is now folded into A01, and A03 broadened "vulnerable components" into the whole software supply chain, which for PHP means Composer 5,243 . composer audit reports any dependency with a published advisory, exiting non-zero so a CI pipeline fails. Over a lock still pinning an old guzzlehttp/psr7 it reports:

Output of 173
Found 5 security vulnerability advisories affecting 1 package:
Package: guzzlehttp/psr7
CVE: CVE-2026-59882
Title: guzzlehttp/psr7: Host Confusion via Weak URI Host Validation
...
exit=1

Composer 2.9+ also refuses by default to add an advisory-affected version (policy.advisories.block); for a stronger guarantee, add roave/security-advisories 2,918 (https://github.com/Roave/SecurityAdvisories 2,918 ) as a dev dependency, whose conflict rules make composer update reject them outright. Subsection 4.12.7 covers the workflow.