Think Build Implement Repeat
London, UK +44 7367 067226
WhatsApp FOLLOW f in X
  1. Home
  2. Blog
  3. Uploads, Storage and Serving Files Safely
PHP Development

Uploads, Storage and Serving Files Safely

Secure file uploads in PHP: store files outside the web root, validate content not extension, serve through permission checks and include them in backups.

Updated 2 min readBy SpiderHunts Technologies

Free estimateNo obligation

Get a free estimate

Tell us what you need. A senior engineer reads every enquiry.

Takes under a minute. We never share your details.

  • Free consultation
  • No commitment
  • NDA on request

Prefer to talk? Book a free 30-minute call →

Quick answer — TL;DR

Store uploads outside the web root, validate content rather than extension, serve through a controller that checks permissions, and never construct paths from user input.

Uploads are a common attack route

A file uploaded into a directory the web server will execute is a straightforward route to running arbitrary code. It is one of the two most common ways PHP applications are compromised.

Storing uploads inside the web root is the mistake. Everything else about upload security is secondary to getting that one thing right.

Upload handling

  1. Store outside the web root, or in object storage
  2. Validate the content, not the filename extension
  3. Generate your own filename; never use the uploaded one
  4. Limit size and type, enforced server-side
  5. Scan where the files will be shared with others

Serving files

Files that should be private must be served through code that checks permissions, not by a direct URL. A guessable URL is not access control.

  • A controller that authenticates, authorises, then streams the file
  • No user input used to build the file path
  • Correct content type and disposition headers
  • Access logged where the documents are sensitive

Where to store them

OptionSuits
Local disk outside web rootSingle server, modest volume
Object storageAnything that may scale or needs redundancy
DatabaseRarely — small files only, and it complicates backups

Object storage is usually the right answer once you have more than one server or more than a few gigabytes.

Include them in backups

Uploaded files are frequently outside the database backup and therefore outside the backup entirely. A restore that recovers the records and not the documents is a partial restore.

Check specifically that your backup includes the file storage, and test a restore of both together.

FAQ

Frequently asked questions

The questions readers ask us after this guide.

Still have a question?

Ask us directly — a senior engineer will get back to you.

Ask about your project

How do we validate file types?

Check the actual content, not the extension or the reported type. Both of those are supplied by the client and can be anything.

Should uploads be scanned?

Where files will be shared with other users, yes. For files only the uploader retrieves, the risk is lower.

What about very large files?

Upload directly to object storage with signed URLs, bypassing your application entirely. That avoids memory and timeout problems.

Are uploaded files in our backups?

Check specifically. They are commonly missed, and it is discovered during a restore.

Keep reading

More on PHP Development

PHP Development

Why PHP Is Still a Sensible Choice

Is PHP still a good choice for business applications? Where modern, typed PHP fits, where another language is better, and the hosting and hiring arguments.

PHP Development

Improving Old Code Without a Rewrite

Modernising a legacy PHP application without a rewrite: move to a supported PHP version, add tests around what matters, then strangle rather than replace.

Start here

Uploads stored in a public directory?

That is the single most exploitable configuration in a PHP application. Worth checking today.

  1. You tell us what you needTwo minutes on the form, or a message on WhatsApp.
  2. A senior engineer reviews itAnd comes back with questions, a realistic range and an honest view on fit.
  3. Free 30-minute scoping callWe talk through scope, options and a realistic estimate — with no obligation.
Free estimateNo obligation

Talk to someone who builds this

Send a short brief and we will come back with an honest view and a realistic range.

Takes under a minute. We never share your details.

  • Free consultation
  • No commitment
  • NDA on request

Prefer to talk? Book a free 30-minute call →