Validate the email before using it: ~~~php $email = filter_var($input, FILTER_VALIDATE_EMAIL); if ($email === false) { throw new InvalidArgumentException('Invalid email address'); } ~~~ Normalize only according to application rules, whitelist allowed values, and still apply authorization and output escaping.
Installs into .claude/skills of the current project.
Are you the author of Php Security?
Add the live security badge to your README. It updates with every re-scan.
[](https://www.skillsdirectory.com/skills/hoangnguyen0403-php-security-4aeff811)
Validate the email before using it:
~~~php
$email = filter_var($input, FILTER_VALIDATE_EMAIL);
if ($email === false) {
throw new InvalidArgumentException('Invalid email address');
}
~~~
Normalize only according to application rules, whitelist allowed values, and still apply authorization and output escaping.