Looking to hire Laravel developers? Try LaraJobs
laravel-jwt-token
Secure JWT authentication for Laravel with rotating refresh tokens, reuse detection, and revocation.
6
laravel-otp
Secure, queued, and configurable OTP verification package for Laravel applications.
37
content-security
Defense-in-depth content security for Laravel: malware scanning, MIME/magic-byte verification, archive/image/PDF inspection, HTML sanitization, URL/SSRF checks, quarantine, audit trail and a Vue 3 security console.
0
laravel-sanitizer
Recursive, filter-based input sanitization for Laravel applications, with per-field rules and dot-notation support.
9
laravel-audit
Enterprise Audit Trails & Compliance Logging for Laravel
2
laravel-antibot
Application-agnostic anti-bot protection for Laravel: risk-based scoring, sliding-window rate limiting, proof-of-work challenges, temporary blocking, and network-verified search engine crawler bypass (Googlebot, Bingbot, YandexBot).
13
laravel-authentication
Production-grade, modular, portable, and secure authentication package for Laravel applications.
45
laravel-secrets-loader
Docker secrets, systemd credentials, and _FILE support for Laravel's env().
3
laravel-guard
Laravel-native security and multi-tenancy analysis for development and CI.
60
laravel-class-obf
Production-grade CSS and HTML class obfuscation library for Laravel applications.
1
laravel-env-audit
Coverage reporting for your .env: static analysis for env() call isolation, .env.example drift, and secret heuristics.
34
funnypot-laravel
Laravel adapter for funnypot: normalise the request, ask the funnypot-policy decision engine, execute the Decision (allow / log / block / deceive). Owns no decision logic.
6
laravel-cors-resolver
A dynamic, request-aware CORS policy resolver for Laravel applications
1
laravel-auth-audit
Authorisation coverage reporting for Laravel applications. Statically scans routes, controllers, Form Requests, and Policies to report what is and is not protected.
70
laravel-device-approval
Laravel package for trusted-device login approval and device-approval security workflows.
1
laravel-login-tracker
Automatic login activity tracking, device fingerprinting, and new-device alerts for Laravel applications.
2
laravel-webhook-signature
Cbox Webhook Signature — verification-only webhook signature checking for Laravel, with drivers for GitHub, Stripe, Slack, Shopify, Standard Webhooks, Twilio, Mailgun and Postal. No migrations, no queue, no models. Secret rotation, replay protection and send-time outbound signing included.
1
laravel-vulns
Multi-source vulnerability lookups for PHP and Laravel: OSV, NVD, GitHub Advisories (registry + repository), EUVD, CVE-Search and Snyk behind one contract.
93
laravel-security-guard
by apkk
Reusable intrusion defence package for Laravel: known attack path detection, permanent IP blocking, public rate limiting, admin IP allowlists, one-time submission tokens and hardened security notifications.
9
laravel-real-client-ip
Laravel middleware that restores the real client IP behind a CDN, load balancer or ingress controller that overwrites X-Forwarded-For, verified with a shared secret so the header cannot be spoofed.
306
laravel-permission
Permission handling for Laravel 12 and up
3
laravel-wraith
Point-in-time static (and opt-in dynamic) diagnostic analysis for Laravel applications — configuration, schema, security, and codebase.
5
laravel-ip-blocker
Laravel package for blocking suspicious IP addresses (anti-spam/anti-scanner). Supports nginx and Apache log parsing.
45
laravel-api-scaffold
Generate clean, secure and configurable Laravel APIs from database tables.
47
laravel-otp
Purpose-scoped, hashed, rate-limited one-time passwords for Laravel.
22
laravel-password
Password policy and lifecycle for Laravel: extended validation rule, blocklists, reuse prevention, expiration, compromise detection and notifications.
7
laravel-source-guard
رمزگذاری امن سورس‌کد PHP در پروژه‌های Laravel/Lumen با مدیریت کلید مبتنی بر Master Key + HKDF
8
laravel-password-rotation
Password rotation for any Laravel app (no admin panel required): force any authenticatable to rotate its password every N days, with reuse prevention, a first-login gate, expiry warnings and a redirect middleware.
227
laravel-ssrf
SSRF prevention for Laravel. Protect Http::, Guzzle, and validate user-supplied URLs against server-side request forgery.
2 781
user-sessions-laravel
Device management, logout other devices and new-device alerts for Laravel — without giving up your cache-based session driver.
115
laravel-purl2cpe
PURL to CPE conversion for Laravel, backed by the curated scanoss/purl2cpe database. Ships ~47k reduced mappings so you can resolve NVD CPEs for a Package URL out of the box.
38
laravel-package-url
Package URL (purl) for Laravel — parse, build, normalize and validate purls per the spec, plus registry/repository/download URL resolution, ecosystem mapping, and CPE-friendly helpers.
41
laravel-watchtower
Intelligent Adaptive Rate Limiter & Security Shield for Laravel - Advanced threat detection, behavioral analysis, fingerprinting, and auto-hardening protection.
0
laravel-mfa
Multi-Factor Authentication package for Laravel with TOTP, Email OTP, and WebAuthn support
11
laravel-risk
Cbox Risk — an explainable, config-driven request risk-scoring pipeline for Laravel. Weights signals (IP reputation, geo, disposable email, velocity, bot timing) into a score and an outcome: allow, challenge, step-up, or reject.
1 052
laravel-ssrf
Cbox SSRF — a hardened, config-driven guard against server-side request forgery for outbound URLs in Laravel. Blocks private/reserved/cloud-metadata targets, pins DNS, and refuses redirects.
2 166
assistant
AI-powered code analysis, security auditing, and health reporting for Laravel applications
0
laravel-fingerprint-tracking
Fingerprint, browser tracking and lightweight page movement tracking for Laravel.
3
laravel-ai-circuit-breaker
An abuse firewall for AI endpoints: detect runaway agent loops within a request, and open a circuit on a per-tenant spend anomaly, before a self-recursing agent drains the API budget. Security-framed, not just rate limiting.
3
laravel-ai-lint
Static analysis for insecure AI wiring in Laravel apps: a scan command that finds AI provider keys leaked into tracked or client-reachable files, plus PHPStan rules that flag model output flowing into unsafe sinks and prompts built by concatenation. SARIF for CI.
6
laravel-ai-egress-guard
Scan, redact, and optionally block outbound requests to AI providers (OpenAI, Anthropic, Gemini, and more) for leaked secrets and PII. Review in an inbox and fail CI before a prompt leaks. SDK-agnostic, at the HTTP layer.
12
laravel-masquerade
Securely assume another user's identity in modern Laravel applications.
5
laravel-secret-scanner
Framework-agnostic secret and PII detection engine: rules, scanner, redactor, severity and confidence model. Shared core for the Laravel Security Audit guard packages.
64
laravel-mail-guard
Scan outgoing Laravel mail for leaked secrets, PII, and compliance issues. Preview, block unsafe sends, and fail CI before email leaks.
0
laravel-vpn-detector
VPN, proxy and Tor detection middleware for Laravel, powered by the IP2Proxy database.
72
laravel-monitoring
Laravel plugin of the mindtwo monitoring suite: framework-specific collectors, a scheduled push job and a signed pull endpoint on top of mindtwo/base-monitoring.
324
laravel-compliance
Map Laravel code evidence to security requirements and generate compliance reports.
38
laravel-encryption
Professional Laravel package for secure encryption with Strategy Pattern, SOLID principles, and modern PHP 8.2+ features
1
unbotable-laravel
Laravel integration for Unbotable — privacy-respecting bot and spam protection
48
laravel-honeypotplus
Laravel package to detect malicious IPs, ban them via Cloudflare, and report to AbuseIPDB
201