Laravel open source
spatie

laravel-settings

1,517 753k installs a month package GitHub
A
A Grade
On the A-List

No critical or high-severity findings

At its latest commit, laravel-settings meets StackShield's A-grade criteria across 39 Laravel-specific security checks. It is rescanned every week and stays on the A-List for as long as it keeps the grade.

What every scan covers

Methodology
Code 11 checks

Mass assignment, SQL and command injection, unescaped output, open redirects and weak password hashing.

Routes 5 checks

Routes resolved the way Laravel registers them: debug routes, missing rate limits, CSRF exemptions, unprotected model binding.

Configuration 12 checks

Debug mode, committed app keys, session cookies, CORS, trusted proxies and production drivers.

Filesystem 5 checks

Environment files, git metadata, backups and unvalidated uploads under public/.

Dependencies 2 checks

Composer packages with published security advisories and Laravel versions past security support.

Show it in your README

The badge updates automatically and links back to this page.

StackShield A grade badge
[![StackShield](https://stackshield.io/oss/badge/spatie/laravel-settings.svg)](https://stackshield.io/oss/repo/spatie/laravel-settings)

Running Laravel in production?

Source code is half the story. StackShield also checks your live app for exposed debug pages, leaked .env files and misconfigured headers.

Scan your app free