Tool and Usage

Project details
LicensePHP License v3.01
Programming languageC
Latest release0.9.38 []

Project health

How it works

Suhosin consists of two parts to achieve its goal. One of them is making a small change to the PHP core to protect PHP applications against attacks like buffer overflows. The second layer of defense includes different security mechanisms to protect against other attacks.

Usage and audience

Suhosin is commonly used for application security. Target users for this tool are developers and system administrators.

Tool review and remarks

The review and analysis of this project resulted in the following remarks for this security tool:


  • + The source code of this software is available


  • - Well-known tool

Author and Maintainers

Supporting company

This project is maintained by SektionEins GmbH



Supported operating systems

Suhosin is known to work on Linux.

Suhosin alternatives

Suhosin7 is the security extension for PHP 7 versions. It protects a PHP installation by preventing different types of attacks.



Iniscan is a security tool to parse the configuration of PHP and provide guidance on best practices. It provides a pass/fail type of output.



Parse is a security scanner to perform static analysis on PHP code potential security-related issues. As it is a static scanner, no code is executed.

Related tool information


This tool is categorized as a PHP hardening tool.