How to audit a Laravel app in 2026
Is a .env on the web root?
Deeper than a manual audit or a tool. At the scale AI agents attack.
The audit starts after signup. $49 for one month. Your report stays in your account.
- Framework version
- Known CVEs
- Secrets and logs
- Debug tools
01 / 08·running
Public surface
Other hosts and open ports
Signals
- Framework versionLaravel or Symfony, and the release your public files give away.
- Known CVEsPublished holes in that framework release.
- Secrets and logs.env, laravel.log, and composer manifests anyone can download.
- Debug toolsTelescope, Horizon, Pulse, Debugbar, and the Symfony profiler.
How the Laravel audit runs
What else is on this domain
Other hostnames on the same domain, then the ports those servers leave open, before anything Laravel-specific.
Subdomains
Staging, old admin hosts, and the other names on your domain.
Live hosts
Which of those names actually answer.
Open ports
What is listening, including the version when the server says it.
On your Laravel
Laravel or Symfony version, then .env, laravel.log, Telescope, Horizon, Debugbar, and the Symfony profiler.
Framework version
Laravel or Symfony, and the release your public files give away.
Known CVEs
Published holes in that framework release.
Secrets and logs
.env, laravel.log, and composer manifests anyone can download.
Debug tools
Telescope, Horizon, Pulse, Debugbar, and the Symfony profiler.
A report you can act on
Each issue names the host, shows the evidence, and says what to fix. Anything we could not confirm stays marked that way.
Evidence
The URL or file that proved it.
CVE ids
Only when we saw the version the advisory is about.
Account
The report opens after the $49 month is paid.
Questions about a Laravel audit
What the run covers, and when the report opens in the account.
Contact usAudit Laravel from the outside.
Deeper than a manual audit or a tool. At the scale AI agents attack.