3v4l.org

run code in 500+ PHP versions simultaneously
<?php $a = "abcdefg\0"; $b = $a . random_bytes(33); // Same prefix, with junk added after the end $hash = password_hash($a, PASSWORD_BCRYPT); // Since $b has junk added to the end, we'd expect this to return // bool(false) var_dump(password_verify($b, $hash));

preferences:
51.37 ms | 1806 KiB | 5 Q