stellarsecurity / laravel-hardening
Stellar Security hardening guard for Laravel (blocks APP_DEBUG=true on production-like hosts).
Package info
github.com/StellarSecurity-Packages/stellar-laravel-hardening
pkg:composer/stellarsecurity/laravel-hardening
v1.0.0
2025-12-10 01:15 UTC
Requires
- php: ^8.0
Requires (Dev)
None
Suggests
None
Provides
None
Conflicts
None
Replaces
None
- dev-main
- v1.0.0
- dev-codex/scanner-log-reader-20260916
- dev-codex/shared-scanner-release-20260916
- dev-codex/scanner-release-20260916-r2
- dev-codex/scanner-release-20260916
- dev-codex/github-commit-trigger-v2-26582986c40b
- dev-codex/github-commit-trigger-3f52783bebb3
- dev-codex/commit-guard-2291b153e87b
- dev-codex/code-push-cbdc607e0124
This package is not auto-updated.
Last update: 2026-10-08 03:11:52 UTC
README
Tiny Laravel package that protects you from pushing APP_DEBUG=true to anything that smells like production.
What it does
- Looks at:
APP_ENV/config('app.env')APP_DEBUG/config('app.debug')- Current HTTP host
WEBSITE_SITE_NAME(Azure App Service)
- If the environment is "production-like" and debug is enabled, it:
- Logs a critical message
- Aborts with HTTP 500
Install
composer require stellarsecurity/laravel-hardening
The service provider is auto-discovered.
Publish the config if you want to tweak the rules:
php artisan vendor:publish --tag=config --provider="Stellar\LaravelHardening\Providers\StellarHardeningServiceProvider"
Then edit config/stellar_hardening.php.