Be part of JetBrains PHPverse 2026 on June 9 – a free online event bringing PHP devs worldwide together.

KLM113's avatar

Are laravel $request parameters sanitized by default?

As title, thanks.

0 likes
8 replies
KLM113's avatar

I'm fine as long as queries are processed through prepared statements, but I'm not sure if this is fully implemented in Laravel, for instance does query builder support them?

jlrdw's avatar
jlrdw
Best Answer
Level 75

Yes except when using raw, there you need to bind the parameters yourself if needed. Taylor has a warning about that in that chapter.

You need to look into validating your request.

1 like
Snapey's avatar

no, the request is not sanitized

jlrdw's avatar

You must be on mobile, on laptop or desktop, there is a best answer to click, show when you hover over.

Please or to participate in this conversation.