Skip to content
Back to skills

Laravel

ASecurity

Build robust Laravel apps avoiding Eloquent traps, queue failures, and auth pitfalls.

  • 14 stars
  • 0 votes
  • 0 copies
  • 2 views
  • Added September 7, 2026
databasesphpapidatabase

Works with

  • api

Security analysis

A100/100

Pro scans all 7 files and shows the line behind each finding

Scanned September 7, 2026

npx -y skills add modbender/skill-library-mcp --skill laravel --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Laravel?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Laravel
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/modbender-laravel/badge)](https://www.skillsdirectory.com/skills/modbender-laravel)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: Laravel
slug: laravel
version: 1.0.1
description: Build robust Laravel apps avoiding Eloquent traps, queue failures, and auth pitfalls.
metadata: {"clawdbot":{"emoji":"🔴","requires":{"bins":["php","composer"]},"os":["linux","darwin","win32"]}}
---

## Quick Reference

| Topic | File |
|-------|------|
| N+1 queries, eager loading, accessors, observers | `eloquent.md` |
| Validation, middleware order, dependency injection | `controllers.md` |
| Job serialization, retries, failed jobs | `queues.md` |
| Guards, policies, gates, Sanctum tokens | `auth.md` |
| XSS escaping, components, slots | `blade.md` |
| Commands, scheduling, tinker | `artisan.md` |

## Critical Rules

- Eager load relationships — `with('posts')` not lazy `->posts` in loop (N+1)
- `preventLazyLoading()` in dev AppServiceProvider — crashes on N+1, catches early
- `env()` only in config files — returns null after `config:cache`
- `$fillable` whitelist fields — `$guarded = []` allows mass assignment attacks
- `find()` returns null — use `findOrFail()` to avoid null checks
- Job properties serialize models as ID — re-fetched on process, may be stale/deleted
- `route:cache` requires controller routes — closures break cached routes
- `DB::transaction()` doesn't catch `exit`/timeout — only exceptions roll back
- `RefreshDatabase` uses transactions — faster than `DatabaseMigrations`
- `{!! $html !!}` skips escaping — XSS vector, use `{{ }}` by default
- Middleware order matters — earlier middleware wraps later execution
- `required` validation passes empty string — use `required|filled` for content
- `firstOrCreate` persists immediately — `firstOrNew` returns unsaved model
- Route model binding uses `id` — override `getRouteKeyName()` for slug

Files in this skill

  • SKILL.md1.8 KB
  • artisan.md564 B
  • auth.md576 B
  • blade.md593 B
  • controllers.md675 B
  • eloquent.md788 B
  • queues.md595 B

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…