All skills
asyrafhussin avatar

/php-best-practices

@e7ea05d

PHP 8.x modern patterns, PSR standards, and SOLID principles. Use when reviewing PHP code, checking type safety, auditing code quality, or ensuring PHP best practices. Triggers on "review PHP", "check PHP code", "audit PHP", or "PHP best practices".

Use this Skill: https://skilld.dev/gh/asyrafhussin/agent-skills/php-best-practices

This session only. Nothing lands on disk.

rulessec-password-hashing.md

≈675 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Password Hashing

Always use password_hash() and password_verify() for password security. Never use MD5, SHA1, or plain text.

Bad Example

<?php

declare(strict_types=1);

// Plain text - worst possible
$password = $_POST['password'];
$db->insert('users', ['password' => $password]);

// MD5 - trivially crackable
$hash = md5($password);

// SHA1 - also trivially crackable
$hash = sha1($password);

// SHA256 without salt - still vulnerable to rainbow tables
$hash = hash('sha256', $password);

// Home-grown "salting" - reinventing the wheel poorly
$hash = hash('sha256', 'mysalt' . $password);

// Comparing hashes with == (timing attack vulnerable)
if ($storedHash == md5($inputPassword)) {
    // login
}

Good Example

<?php

declare(strict_types=1);

// Hash with bcrypt (default) or Argon2id (recommended)
$hash = password_hash($password, PASSWORD_ARGON2ID);
// Or: password_hash($password, PASSWORD_DEFAULT); // bcrypt

// Verify - timing-safe comparison built in
if (password_verify($inputPassword, $storedHash)) {
    // Password correct

    // Rehash if algorithm or cost changed
    if (password_needs_rehash($storedHash, PASSWORD_ARGON2ID)) {
        $newHash = password_hash($inputPassword, PASSWORD_ARGON2ID);
        $repository->updatePasswordHash($userId, $newHash);
    }

    // Regenerate session after login
    session_regenerate_id(true);
}

// Custom Argon2id options for high-security applications
$hash = password_hash($password, PASSWORD_ARGON2ID, [
    'memory_cost' => 65536,  // 64MB
    'time_cost' => 4,        // 4 iterations
    'threads' => 3,          // 3 threads
]);

// Password validation before hashing
function validatePassword(string $password): void
{
    if (mb_strlen($password) < 8) {
        throw new ValidationException(['password' => 'Minimum 8 characters']);
    }
    if (strlen($password) > 72) {
        // bcrypt truncates at 72 bytes - strlen counts bytes
        throw new ValidationException(['password' => 'Password too long']);
    }
}

Why

  • Argon2id: Memory-hard algorithm resistant to GPU/ASIC attacks
  • Automatic Salting: password_hash generates a unique salt per password
  • Timing-Safe: password_verify prevents timing attacks
  • Future-Proof: password_needs_rehash upgrades hashes when algorithm changes
  • bcrypt Limit: bcrypt truncates passwords at 72 bytes - validate max length
  • PASSWORD_DEFAULT: Currently bcrypt, will change to best available algorithm

Source: SKILL.md on GitHub

No alerts17d5 checks · Risk SAFE
  • Gen Agent Trust Hub17d

    This skill is a comprehensive and safe resource for PHP 8.x best practices. It provides structured guidance on type safety, modern PHP syntax, PSR standards, and secure coding practices (such as prepared statements and password hashing). The agent is instructed to use standard environment detection commands (php -v, grep) to tailor its advice. No malicious patterns or security risks were identified.

  • Socket17d

    No alerts

  • Snyk17d

    Risk: LOW · No issues

  • Runlayer6mo

    39 files scanned · No issues

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at e7ea05d. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub last month.

Steadyupdated 7 months ago
Other metadata
metadata
{
  "author": "php-community",
  "version": "2.1.0",
  "phpVersion": "8.0 - 8.5"
}

README badge

README badge for asyrafhussin/agent-skills/php-best-practices