Works with the AI tools you already use
Laravel Security Hardening Review
Turn a Laravel codebase into a severity-ranked, exploit-traced security report with Laravel-native fixes your team can ship before release.
Free
Laravel Security Hardening Review
Example session with this skill installed
We're a week from launching a multi-tenant Laravel 11 SaaS and I need a pre-release security review. The code is in ./api — check routes/api.php, the PostController and BillingController, the User and Invoice models, all form requests, and .env.production. I'm especially worried about the invoice file upload endpoint and the reporting endpoints that take a user-supplied sort column. Give me severity-ranked findings with exact file references and the smallest Laravel-native fix for each, plus a short list of anything that must be fixed before we accept production traffic.
- Read your context and instructions
- Compiled the laravel security hardening
- Generated the document
Summary
Security review of shopfront-api (Laravel 11, multi-tenant): 14 findings across 9 entry points — 2 critical, 4 high. All fixes are Laravel-native and fit in one PR cycle; authorization and upload issues should ship before the next deploy.
| Severity | Finding | Location | Fix |
|---|---|---|---|
| Critical | Debug mode + .env web-exposed | .env.production, public/ | APP_DEBUG=false, move env out of docroot |
| High | create($request->all()) allows role/tenant_id injection | UserController::store | Whitelist via FormRequest::validated() |
| High | Invoice lookup by ID without tenant scoping (IDOR) | InvoiceController::show | Invoice::where('tenant_id', $user->tenant_id)->findOrFail($id) |
| High | User-controlled sort column into orderByRaw | ReportController | match() whitelist for sort + direction |
| Medium | Invoice uploads to public disk with original filename | UploadController | Private disk + Str::uuid() filenames |
| Medium | No throttle:api on password reset | routes/auth.php | Add throttle + single-use tokens |
Next steps
- Merge PR #482 (critical + high fixes) and re-run this audit pre-release
- Add policy coverage to
PostandInvoicemodels; enforce in CI - Purge PII from queued job payloads; pass model IDs instead
- Re-audit webhooks and Sanctum token scopes after the next sprint
laravel-security-hardening-review.pdf
PDF · document
Example file from a real run - the skill writes it into your workspace.
Connects securely to your tools. The creator never sees your data.
About this skill
Laravel applications often ship with hidden vulnerabilities in trust boundaries, request handling, and authorization. This skill transforms your Laravel codebase into a severity-ranked, exploit-traced security report with framework-native fixes.
What it does
- Vulnerability discovery identifies missing authorization checks, object ID enumeration, and mass assignment risks.
- Input trust analysis reviews form requests, validation rules, and raw SQL interpolation.
- Auth audit inspects login flows, session safety, and token revocation strategies.
- Infrastructure hardening checks for
.envexposure, debug mode leaks, and CORS misconfigurations. - Native remediation provides concise, idiomatic Laravel code fixes for every finding.
How it works
- App Mapping defines the application type and maps all external entry points like routes, webhooks, and queues.
- Input Tracing follows untrusted data from query strings or JSON bodies to sensitive sinks like the database or file system.
- Severity Ranking categorizes findings from Critical to Informational based on real-world exploitability.
- Fix Generation outputs a prioritized remediation report with specific code examples for your team.
Frameworks & tools
Laravel 8.x through 11.x, Eloquent ORM, Laravel Sanctum, Blade templating, and PHP 8.x security standards.
Why this beats prompting it yourself
Generic security prompts often suggest unnecessary third-party packages or ignore Laravel features like Policy-based authorization and FormRequests. This skill uses the framework's own architecture to secure the app, ensuring fixes are maintainable and idiomatic.
Use cases
- Auditing a legacy Laravel app before a major version upgrade.
- Performing a pre-release security checklist for new API endpoints.
- Reviewing third-party integrations, webhooks, and queued jobs for data leaks.
- Training junior developers by showing exploit paths in their PRs.
Known limitations
This skill focuses on the Laravel application layer. It does not audit low-level server OS hardening, network firewalls, or third-party PHP packages outside the Laravel ecosystem.
How to install
Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.
- 1
Download the ZIP
Free skills download straight away. Paid skills unlock right after purchase.
- 2
Unzip into your skills folder
Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.
- 3
Ask your agent to use it
Restart the agent if it was already running. It picks the skill up automatically - no config needed.
Skills folder by agent
Click the path to copy it. Create the folder if it does not exist yet.
Reviews
No reviews yet
Be one of the first to try it. Every listed skill passes our trust checks below.
Security scanned
Passed our 8-point scan before listing
1 install
Downloaded by developers to date
Free forever
No account required to browse
Trust & safety
Security scanned
Verified clean 6 days ago
- Free to download with an account