PHPackages                             dhanikkeraliya/laravel-securescan - PHPackages - PHPackages  [Skip to content](#main-content)[PHPackages](/)[Directory](/)[Categories](/categories)[Trending](/trending)[Leaderboard](/leaderboard)[Changelog](/changelog)[Analyze](/analyze)[Collections](/collections)[Log in](/login)[Sign up](/register)

1. [Directory](/)
2. /
3. [Security](/categories/security)
4. /
5. dhanikkeraliya/laravel-securescan

ActiveLibrary[Security](/categories/security)

dhanikkeraliya/laravel-securescan
=================================

A powerful security scanner for Laravel applications with CLI and web dashboard support to detect vulnerabilities like SQL Injection, XSS, secrets, and misconfigurations.

v1.0.1(3mo ago)812MITPHPPHP ^8.1

Since Apr 19Pushed 3mo agoCompare

[ Source](https://github.com/dhanikkeraliya/laravel-securescan)[ Packagist](https://packagist.org/packages/dhanikkeraliya/laravel-securescan)[ Docs](https://github.com/dhanikkeraliya/laravel-securescan)[ RSS](/packages/dhanikkeraliya-laravel-securescan/feed)WikiDiscussions main Synced 1w ago

READMEChangelog (1)Dependencies (2)Versions (2)Used By (0)

🔐 Laravel SecureScan - Security Scanner for Laravel Applications
================================================================

[](#-laravel-securescan---security-scanner-for-laravel-applications)

![Latest Version](https://camo.githubusercontent.com/3c6d636bd963dc6708918a114b88142e3bb216a50a1f28b28e48e897107462b1/68747470733a2f2f696d672e736869656c64732e696f2f7061636b61676973742f762f6468616e696b6b6572616c6979612f6c61726176656c2d7365637572657363616e2e7376673f7374796c653d666c61742d737175617265)[![License](https://camo.githubusercontent.com/ac049ef4e7a0b7196b09add6ac2d4f180e544c0ac779c2b2ac2fd2723a209579/68747470733a2f2f696d672e736869656c64732e696f2f62616467652f6c6963656e73652d4d49542d626c75653f7374796c653d666c61742d737175617265)](LICENSE)![PHP Version](https://camo.githubusercontent.com/bf4bda9d4d0ed45dda848717371d8b1854e1002a3d0bf0990030ff55b143d5c9/68747470733a2f2f696d672e736869656c64732e696f2f62616467652f7068702d253345253344382e312d626c75653f7374796c653d666c61742d737175617265)![Laravel](https://camo.githubusercontent.com/e11e1fcfea0a5de5f2da2aba4aa0e4b40fb0d3cd22cb34fa2bc09cf36c0528de/68747470733a2f2f696d672e736869656c64732e696f2f62616467652f6c61726176656c2d39253230746f25323031312d7265643f7374796c653d666c61742d737175617265)

---

🚀 Overview
----------

[](#-overview)

**Laravel SecureScan** is a powerful security analysis tool for Laravel applications.

\##🔥 Real-time Laravel security scanner with live dashboard (no queue required)

It scans your codebase to detect:

- 🔴 Critical vulnerabilities (SQL Injection, XSS, Secrets)
- 🟡 Security misconfigurations
- 🟢 Best practice issues

It provides:

- ⚡ CLI-based scanning
- 📊 Real-time web dashboard
- 📁 Detailed findings with fixes

---

🔥 Features
----------

[](#-features)

### ✅ CLI Scanner

[](#-cli-scanner)

- Real-time progress bar
- Colored severity output
- Detailed issue + fix suggestions

### ✅ Web Dashboard

[](#-web-dashboard)

- Live scanning (no queue required)
- Progress tracking
- Severity charts (High / Medium / Low)
- Live logs (terminal-style)
- Findings table

### ✅ Security Checks

[](#-security-checks)

#### 🔴 High Severity

[](#-high-severity)

- SQL Injection detection
- XSS vulnerabilities
- Hardcoded secrets
- ENV exposure
- Dangerous PHP functions
- Sensitive data logging

#### 🟡 Medium Severity

[](#-medium-severity)

- Missing authorization
- Mass assignment issues
- File upload risks
- Open redirects
- Rate limiting issues
- Unvalidated input

#### 🟢 Low Severity

[](#-low-severity)

- Weak random usage
- Hardcoded URLs

---

📦 Installation
--------------

[](#-installation)

```
composer require dhanikkeraliya/laravel-securescan
```

---

⚙️ Configuration
----------------

[](#️-configuration)

Publish config:

```
php artisan vendor:publish --tag=securescan-config
```

---

🔍 Usage
-------

[](#-usage)

### CLI Scan

[](#cli-scan)

```
php artisan security:scan
```

---

### Web Dashboard

[](#web-dashboard)

```
http://localhost:8000/_securescan
```

🚫 Ignore Rules (`.securescan-ignore`)
-------------------------------------

[](#-ignore-rules-securescan-ignore)

Laravel SecureScan allows you to ignore specific files, patterns, or rules using a `.securescan-ignore` file placed in the **project root**.

This helps reduce noise and avoid false positives in your scans.

---

### 📄 Example

[](#-example)

Create a file:

```
.securescan-ignore
```

Add rules like:

```
# Ignore specific files
app/Models/Test.php

# Ignore by pattern
*/Seeder.php

# Ignore by rule
SQL Injection
XSS
```

---

### 🔍 Supported Ignore Types

[](#-supported-ignore-types)

#### 1. Ignore Specific File

[](#1-ignore-specific-file)

```
app/Models/Test.php
```

#### 2. Ignore by Pattern

[](#2-ignore-by-pattern)

```
*/Seeder.php
```

#### 3. Ignore by Rule Type

[](#3-ignore-by-rule-type)

```
SQL Injection
XSS
```

---

### ⚙️ Usage

[](#️-usage)

Run scan with ignore rules enabled:

```
php artisan security:scan --ignore
```

---

### ⚠️ Important Notes

[](#️-important-notes)

- Ignore rules are applied **after scan results are generated**
- Rule matching is based on:

    - File path
    - Finding type (e.g., SQL Injection)
- Keep rules minimal to avoid hiding real vulnerabilities

---

### 💡 Best Practice

[](#-best-practice)

Use ignore rules only when:

- You have verified a false positive
- The issue is intentionally handled in your code

Avoid blindly ignoring critical issues.

---

---

🖥️ Dashboard Preview
--------------------

[](#️-dashboard-preview)

[![image](https://private-user-images.githubusercontent.com/52264894/580399857-f211c83c-08d2-4669-a15d-f2fd792ad549.png?jwt=eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJpc3MiOiJnaXRodWIuY29tIiwiYXVkIjoicmF3LmdpdGh1YnVzZXJjb250ZW50LmNvbSIsImtleSI6ImtleTUiLCJleHAiOjE3ODM4NTkzMjMsIm5iZiI6MTc4Mzg1OTAyMywicGF0aCI6Ii81MjI2NDg5NC81ODAzOTk4NTctZjIxMWM4M2MtMDhkMi00NjY5LWExNWQtZjJmZDc5MmFkNTQ5LnBuZz9YLUFtei1BbGdvcml0aG09QVdTNC1ITUFDLVNIQTI1NiZYLUFtei1DcmVkZW50aWFsPUFLSUFWQ09EWUxTQTUzUFFLNFpBJTJGMjAyNjA3MTIlMkZ1cy1lYXN0LTElMkZzMyUyRmF3czRfcmVxdWVzdCZYLUFtei1EYXRlPTIwMjYwNzEyVDEyMjM0M1omWC1BbXotRXhwaXJlcz0zMDAmWC1BbXotU2lnbmF0dXJlPTViNzhhYjZjNjg3Nzc2NGU0MGFiMGM5YjI5M2ZhZmI3ZjY1YWQzNmU0NDZmODQzNWFmMTI4OTE5NTZjNmZlODQmWC1BbXotU2lnbmVkSGVhZGVycz1ob3N0JnJlc3BvbnNlLWNvbnRlbnQtdHlwZT1pbWFnZSUyRnBuZyJ9.Ema6LpHGAG_LN_nsEqWomW2c250RfqlC5FYgN1TzlsE)](https://private-user-images.githubusercontent.com/52264894/580399857-f211c83c-08d2-4669-a15d-f2fd792ad549.png?jwt=eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJpc3MiOiJnaXRodWIuY29tIiwiYXVkIjoicmF3LmdpdGh1YnVzZXJjb250ZW50LmNvbSIsImtleSI6ImtleTUiLCJleHAiOjE3ODM4NTkzMjMsIm5iZiI6MTc4Mzg1OTAyMywicGF0aCI6Ii81MjI2NDg5NC81ODAzOTk4NTctZjIxMWM4M2MtMDhkMi00NjY5LWExNWQtZjJmZDc5MmFkNTQ5LnBuZz9YLUFtei1BbGdvcml0aG09QVdTNC1ITUFDLVNIQTI1NiZYLUFtei1DcmVkZW50aWFsPUFLSUFWQ09EWUxTQTUzUFFLNFpBJTJGMjAyNjA3MTIlMkZ1cy1lYXN0LTElMkZzMyUyRmF3czRfcmVxdWVzdCZYLUFtei1EYXRlPTIwMjYwNzEyVDEyMjM0M1omWC1BbXotRXhwaXJlcz0zMDAmWC1BbXotU2lnbmF0dXJlPTViNzhhYjZjNjg3Nzc2NGU0MGFiMGM5YjI5M2ZhZmI3ZjY1YWQzNmU0NDZmODQzNWFmMTI4OTE5NTZjNmZlODQmWC1BbXotU2lnbmVkSGVhZGVycz1ob3N0JnJlc3BvbnNlLWNvbnRlbnQtdHlwZT1pbWFnZSUyRnBuZyJ9.Ema6LpHGAG_LN_nsEqWomW2c250RfqlC5FYgN1TzlsE)### CLI Output

[](#cli-output)

[![image](https://private-user-images.githubusercontent.com/52264894/580399825-ce8e0f12-3fb0-41f7-8e4f-9f10a0df1a50.png?jwt=eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJpc3MiOiJnaXRodWIuY29tIiwiYXVkIjoicmF3LmdpdGh1YnVzZXJjb250ZW50LmNvbSIsImtleSI6ImtleTUiLCJleHAiOjE3ODM4NTkzMjMsIm5iZiI6MTc4Mzg1OTAyMywicGF0aCI6Ii81MjI2NDg5NC81ODAzOTk4MjUtY2U4ZTBmMTItM2ZiMC00MWY3LThlNGYtOWYxMGEwZGYxYTUwLnBuZz9YLUFtei1BbGdvcml0aG09QVdTNC1ITUFDLVNIQTI1NiZYLUFtei1DcmVkZW50aWFsPUFLSUFWQ09EWUxTQTUzUFFLNFpBJTJGMjAyNjA3MTIlMkZ1cy1lYXN0LTElMkZzMyUyRmF3czRfcmVxdWVzdCZYLUFtei1EYXRlPTIwMjYwNzEyVDEyMjM0M1omWC1BbXotRXhwaXJlcz0zMDAmWC1BbXotU2lnbmF0dXJlPTg0MmIxNzQzYjk5ZjAzZWJjOTIxZTQ0NTRhNWQ1MjQ1MDE0NTkwZTE0MjY2NGViNmZlYmMwMmQwMGY4YmI5YTAmWC1BbXotU2lnbmVkSGVhZGVycz1ob3N0JnJlc3BvbnNlLWNvbnRlbnQtdHlwZT1pbWFnZSUyRnBuZyJ9.1CFMrHxVPqDoGx-yG2UCWszE-AxYpm-pRC2eT47EaSo)](https://private-user-images.githubusercontent.com/52264894/580399825-ce8e0f12-3fb0-41f7-8e4f-9f10a0df1a50.png?jwt=eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJpc3MiOiJnaXRodWIuY29tIiwiYXVkIjoicmF3LmdpdGh1YnVzZXJjb250ZW50LmNvbSIsImtleSI6ImtleTUiLCJleHAiOjE3ODM4NTkzMjMsIm5iZiI6MTc4Mzg1OTAyMywicGF0aCI6Ii81MjI2NDg5NC81ODAzOTk4MjUtY2U4ZTBmMTItM2ZiMC00MWY3LThlNGYtOWYxMGEwZGYxYTUwLnBuZz9YLUFtei1BbGdvcml0aG09QVdTNC1ITUFDLVNIQTI1NiZYLUFtei1DcmVkZW50aWFsPUFLSUFWQ09EWUxTQTUzUFFLNFpBJTJGMjAyNjA3MTIlMkZ1cy1lYXN0LTElMkZzMyUyRmF3czRfcmVxdWVzdCZYLUFtei1EYXRlPTIwMjYwNzEyVDEyMjM0M1omWC1BbXotRXhwaXJlcz0zMDAmWC1BbXotU2lnbmF0dXJlPTg0MmIxNzQzYjk5ZjAzZWJjOTIxZTQ0NTRhNWQ1MjQ1MDE0NTkwZTE0MjY2NGViNmZlYmMwMmQwMGY4YmI5YTAmWC1BbXotU2lnbmVkSGVhZGVycz1ob3N0JnJlc3BvbnNlLWNvbnRlbnQtdHlwZT1pbWFnZSUyRnBuZyJ9.1CFMrHxVPqDoGx-yG2UCWszE-AxYpm-pRC2eT47EaSo)Why SecureScan?
---------------

[](#why-securescan)

Most Laravel security tools:

- Only scan dependencies ❌
- No UI ❌
- No real-time feedback ❌

SecureScan provides:

- Code-level scanning ✅
- Real-time dashboard ✅
- Developer-friendly output ✅

---

🤝 Contributing
--------------

[](#-contributing)

Contributions are welcome!

Steps:

1. Fork the repo
2. Create feature branch
3. Submit PR

---

🔐 Security
----------

[](#-security)

If you find any vulnerabilities, please check [SECURITY.md](SECURITY.md).

---

📄 License
---------

[](#-license)

MIT License

###  Health Score

37

—

LowBetter than 81% of packages

Maintenance82

Actively maintained with recent releases

Popularity11

Limited adoption so far

Community6

Small or concentrated contributor base

Maturity42

Maturing project, gaining track record

 Bus Factor1

Top contributor holds 100% of commits — single point of failure

How is this calculated?**Maintenance (25%)** — Last commit recency, latest release date, and issue-to-star ratio. Uses a 2-year decay window.

**Popularity (30%)** — Total and monthly downloads, GitHub stars, and forks. Logarithmic scaling prevents top-heavy scores.

**Community (15%)** — Contributors, dependents, forks, watchers, and maintainers. Measures real ecosystem engagement.

**Maturity (30%)** — Project age, version count, PHP version support, and release stability.

###  Release Activity

Cadence

Unknown

Total

1

Last Release

97d ago

### Community

Maintainers

![](https://avatars.githubusercontent.com/u/52264894?v=4)[dhanikkeraliya](/maintainers/dhanikkeraliya)[@dhanikkeraliya](https://github.com/dhanikkeraliya)

---

Top Contributors

[![dhanikkeraliya](https://avatars.githubusercontent.com/u/52264894?v=4)](https://github.com/dhanikkeraliya "dhanikkeraliya (6 commits)")

---

Tags

phplaravelsecuritycode analysisxssSQL Injectionscannervulnerability

### Embed Badge

![Health badge](/badges/dhanikkeraliya-laravel-securescan/health.svg)

```
[![Health](https://phpackages.com/badges/dhanikkeraliya-laravel-securescan/health.svg)](https://phpackages.com/packages/dhanikkeraliya-laravel-securescan)
```

###  Alternatives

[larastan/larastan

Larastan - Discover bugs in your code without running it. A phpstan/phpstan extension for Laravel

6.5k55.4M9.2k](/packages/larastan-larastan)[laravel/sail

Docker files for running a basic Laravel application.

1.9k205.7M1.3k](/packages/laravel-sail)[laravel/ai

The official AI SDK for Laravel.

1.0k3.2M246](/packages/laravel-ai)[calebdw/larastan

Larastan - Discover bugs in your code without running it. A phpstan/phpstan extension for Laravel

15118.7k4](/packages/calebdw-larastan)[laravel/surveyor

Static analysis tool for Laravel applications.

86121.4k14](/packages/laravel-surveyor)[tomshaw/electricgrid

A feature-rich Livewire package designed for projects that require dynamic, interactive data tables.

119.4k](/packages/tomshaw-electricgrid)

PHPackages © 2026

[Directory](/)[Categories](/categories)[Trending](/trending)[Changelog](/changelog)[Analyze](/analyze)
