Field Manual PHP / Laravel reference
← Security

Password hashing

Password hashes allow verification without storing plaintext.

What it is

Password hashes allow verification without storing plaintext.

When to use it

Use adaptive framework/PHP password functions.

Syntax

// Bad: md5($password) or plaintext
// Good:
$hash = password_hash($password, PASSWORD_DEFAULT);
$valid = password_verify($password, $hash);

Example

use Illuminate\Support\Facades\Hash;
$user->password = Hash::make($validatedPassword);
$user->save();
$valid = Hash::check($candidate, $user->password);

Common mistakes

Do not invent salts or algorithms; hashing is not reversible encryption; avoid silently truncating long passwords.

Related topics

Browse Security