Description
rand, mt_rand, uniqid, and str_shuffle are unsuitable for generating security tokens or authentication codes.
Potential impact
Predictable values may allow token guessing, authentication bypass, or session hijacking.
Remediation
Use random_bytes or random_int for security-sensitive random values.
Examples
Before
php
<?php
$token = uniqid();
After
php
<?php
$token = bin2hex(random_bytes(32));
Explanation:
- Before: A predictable generator is used for a security-sensitive token.
- After: The token is generated from cryptographically secure random bytes.