No critical or high-severity findings
At its latest commit, octane meets StackShield's A-grade criteria across 39 Laravel-specific security checks. It is rescanned every week and stays on the A-List for as long as it keeps the grade.
What every scan covers
MethodologyMass assignment, SQL and command injection, unescaped output, open redirects and weak password hashing.
Routes resolved the way Laravel registers them: debug routes, missing rate limits, CSRF exemptions, unprotected model binding.
Debug mode, committed app keys, session cookies, CORS, trusted proxies and production drivers.
Environment files, git metadata, backups and unvalidated uploads under public/.
Composer packages with published security advisories and Laravel versions past security support.
Show it in your README
The badge updates automatically and links back to this page.
[](https://stackshield.io/oss/repo/laravel/octane)
Running Laravel in production?
Source code is half the story. StackShield also checks your live app for exposed debug pages, leaked .env files and misconfigured headers.