Blog

Security insights, Laravel best practices, and product updates.

March 2026 · 8 min read

Rate Limiting and Throttling in Laravel APIs

Your API is a front door. Without rate limiting, you've left it propped open. Named limiters, multi-dimensional keys, plan-based throttling, sliding windows — here's how to do it properly.

Read more →
March 2026 · 6 min read

5 Laravel Security Mistakes Your SAST Scanner Misses

Generic SAST tools were built for Java apps. Here are five real Laravel vulnerabilities they miss — unscoped route model binding, nested relationship mass assignment, cache tenant leakage, and more.

Read more →
March 2026 · 8 min read

Introducing HAVOC: Framework-Aware Security Scanning for Laravel

The problem with your current security scanner isn't that it misses vulnerabilities — it's that it's crying wolf so loudly you've stopped listening. HAVOC changes that.

Read more →