Vulnerability scanning
The CVE in a package you did not know you had
LaraBug reads your composer.lock and tells you which of your dependencies have known vulnerabilities, how bad each one is, and the version that fixes it.
In the same list as everything else
Findings arrive as issues, next to your exceptions. There is no second dashboard to remember to check, and they snooze, assign and notify the same way.
- Severity, the affected version range and the first safe version
- Rescanned when the advisory database moves, not only when you deploy
- The same notification channels your exceptions use
Keep reading
Start catching what your users do not report
Free to start and no card needed. Require the package, paste your project key, and the next exception is in your inbox before you have finished reading this.