30+ Automated Security Checks
StackShield continuously monitors your Laravel application from the outside, running comprehensive security checks so you can catch vulnerabilities before attackers do.
application security
11 checks in this category
Laravel Ignition Exposure
Checks if Laravel Ignition error page is exposed in production.
Laravel Telescope Exposure
Checks if Laravel Telescope debugging tool is exposed in production.
Laravel Debug Mode
Checks if Laravel debug mode is enabled in production.
CSRF Protection
Verifies CSRF token implementation on forms and APIs.
File Upload Security
Tests file upload endpoints for security vulnerabilities.
Session Configuration
Validates session security settings and configuration.
Nikto Web Server Scan
Scans web servers for dangerous files, outdated software, and misconfigurations using Nikto. Requires domain verificatio...
SQL Injection Scan
Automated SQL injection detection and testing using SQLMap. Requires domain verification.
Technology Fingerprinting
Identifies web technologies, frameworks, and their versions for vulnerability assessment using WhatWeb.
WordPress Security Scan
Scans WordPress sites for vulnerable plugins, themes, and core version issues using WPScan.
Web Application Vulnerability Scan
Scans web applications for XSS, XXE, SSRF, and other OWASP vulnerabilities using Wapiti. Requires domain verification.
authentication authorization
4 checks in this category
Brute Force Protection
Tests if login page blocks repeated failed login attempts.
JWT Token Security
Detects weak JWT tokens (HS256, missing exp).
CORS Misconfiguration
Identifies insecure CORS headers (Access-Control-Allow-Origin: *).
API Rate Limiting
Checks if API endpoints implement proper rate limiting.
email domain security
4 checks in this category
Subdomain Takeover
Detects unclaimed subdomains pointing to external services.
Email Security
Checks email configuration for security best practices.
DNS Reconnaissance
Comprehensive DNS enumeration and zone transfer testing using DNSRecon.
Subdomain Discovery
DNS reconnaissance and subdomain discovery using Fierce.
file directory security
4 checks in this category
Exposed .env Files
Checks if .env files are publicly accessible.
Directory & File Exposure
Scans for publicly accessible sensitive files (logs, .git).
Sensitive Laravel Files
Checks for exposed sensitive Laravel files (.git, logs, config).
Directory Bruteforce Scan
Discovers hidden directories and files using dictionary-based brute forcing with Gobuster. Requires domain verification.
infrastructure security
7 checks in this category
Security Headers
Detects missing headers (CSP, HSTS, X-Frame-Options).
SSL/TLS Security
Checks SSL expiration, weak ciphers, and HSTS.
Cloud Storage Exposure
Detects public AWS S3, GCP, and DigitalOcean buckets.
Nmap Port Scanning
Comprehensive network and port scanning with service version detection using Nmap.
IP Reputation
Checks if the domain IP is listed in abuse databases.
DNS Security
Checks DNS configuration and security settings.
WAF Detection
Detects the presence and type of Web Application Firewall protecting the target using wafw00f.
Run All These Checks on Your Laravel App
Get started with a 14-day free trial. No installation required — StackShield monitors your app from the outside.
Start Free Trial