nivoin / ship-ready
Security, performance and production-readiness auditor for Laravel 9–13+
Requires
- php: ^8.0
- illuminate/console: ^9.0|^10.0|^11.0|^12.0|^13.0
- illuminate/contracts: ^9.0|^10.0|^11.0|^12.0|^13.0
- illuminate/support: ^9.0|^10.0|^11.0|^12.0|^13.0
- nikic/php-parser: ^4.0|^5.0
- spatie/laravel-package-tools: ^1.9
- symfony/finder: ^6.0|^7.0
Requires (Dev)
- orchestra/testbench: ^7.0|^8.0|^9.0|^10.0|^11.0
- pestphp/pest: ^2.0|^3.0
- pestphp/pest-plugin-laravel: ^2.0|^3.0
Suggests
None
Provides
None
Conflicts
None
Replaces
None
This package is auto-updated.
Last update: 2026-10-01 18:01:06 UTC
README
<<<<<<< HEAD
ShipReady
Security, performance, and production-readiness auditor for Laravel 9–13+.
Installation
composer require nivoin/ship-ready --dev
Usage
Run all checks against production:
php artisan ship:check --env=production
Run only security checks:
php artisan ship:check --category=security
Output as JSON for CI:
php artisan ship:check --format=json --output=ship-ready-report.json
Output SARIF for GitHub Code Scanning:
php artisan ship:check --format=sarif --output=results.sarif
Commands
| Command | Description |
|---|---|
ship:check |
Run all checks and report findings |
ship:baseline |
Record current findings as baseline (suppress them) |
ship:explain {ID} |
Show detailed explanation for a check |
ship:list |
List all available checks |
make:ship-check {Name} |
Generate a custom check class |
Options for ship:check
| Option | Default | Description |
|---|---|---|
--env |
production |
Target environment |
--category |
all | Filter by category |
--check |
all | Run a single check by ID |
--format |
console |
Output format: console, json, sarif, junit, markdown, html, github |
--output |
stdout | Write report to file |
--fail-on |
high |
Minimum severity to exit non-zero |
--compact |
false | Compact output without fix hints |
--ignore-baseline |
false | Run all checks ignoring baseline |
Checks
Security (26 checks)
| ID | Title | Severity |
|---|---|---|
| SEC001 | Debug mode enabled in production | critical |
| SEC002 | Application key missing or insecure | critical |
| SEC003 | Vulnerable Composer packages | high |
| SEC004 | Vulnerable npm packages | high |
| SEC005 | Model with no fillable/guarded | high |
| SEC006 | Model::unguard() outside seeders | high |
| SEC007 | $request->all() mass assignment | high |
| SEC008 | Raw Blade output {!! !!} | medium |
| SEC009 | SQL injection in raw queries | critical |
| SEC010 | Auth routes without throttle | high |
| SEC011 | CSRF exclusions | medium |
| SEC012 | Insecure session cookie config | high |
| SEC013 | APP_URL using HTTP | high |
| SEC014 | Missing security headers | medium |
| SEC015 | CORS wildcard + credentials | critical |
| SEC016 | Debug tools exposed in production | high |
| SEC017 | Sensitive files in public/ | critical |
| SEC018 | env() outside config files | medium |
| SEC019 | Hardcoded secrets in source | critical |
| SEC020 | Dangerous PHP functions | critical |
| SEC021 | Unvalidated file uploads | high |
| SEC022 | Admin routes without authorization | high |
| SEC023 | Sanctum token never expires | medium |
| SEC024 | Weak password hashing | high |
| SEC025 | signedRoute without signed middleware | medium |
| SEC026 | Open redirect vulnerability | high |
Performance (14 checks)
PERF001–PERF014: Config/Route/View caching, OPcache, autoloader optimization, slow cache drivers, N+1 queries, missing indexes, and more.
Reliability (14 checks)
REL001–REL014: Pending migrations, scheduler, queue config, mail driver, storage permissions, health routes, .env.example sync, and more.
Version-Specific (6 checks)
VER001–VER006: Laravel 11+ middleware changes, Reverb TLS, AI SDK keys, passkey config, and more.
Baseline
Suppress known issues without fixing them immediately:
# Record all current findings as baseline php artisan ship:baseline # Remove resolved findings from baseline php artisan ship:baseline --prune
Custom Checks
Generate a check:
php artisan make:ship-check MyCustomCheck --category=security --severity=high
This creates app/ShipReady/MyCustomCheck.php. Custom checks are auto-discovered.
Configuration
Publish the config:
php artisan vendor:publish --tag=ship-ready-config
Key options in config/ship-ready.php:
checks— null (all) or array of check class namesdisabled— array of check IDs to skipseverity_overrides— override severity per check IDfail_on— minimum severity to exit non-zero (env:SHIP_READY_FAIL_ON)baseline— path to baseline JSON fileeditor— editor for file links (env:SHIP_READY_EDITOR)
CI Integration
GitHub Actions:
- name: Run ShipReady run: php artisan ship:check --env=production --format=github
SARIF upload:
- name: Run ShipReady run: php artisan ship:check --format=sarif --output=results.sarif - name: Upload SARIF uses: github/codeql-action/upload-sarif@v3 with: sarif_file: results.sarif
License
MIT