Operate with evidence.
Use this guide to install the package, run scans, interpret findings, and harden the workflow around it.
Installation
Laravel Scalpel requires PHP 8.2+ and supports Laravel 10 through 13.
composer require hryagstn/laravel-scalpel
php artisan vendor:publish --tag=scalpel-configCommands
php artisan scalpel:scanScan for structural, obfuscation, server-rule, and environment findings.php artisan scalpel:baselineSave a trusted cryptographic snapshot of the project.php artisan scalpel:diffCompare the current filesystem against the saved baseline.php artisan scalpel:verifyVerify the integrity signature on a signed report.Configuration
Adjust config/scalpel.php to declare non-PHP zones, allowed files, excluded paths, obfuscation patterns, severity thresholds, and report signing.
'non_php_zones' => ['public', 'storage'],
'excluded_paths' => ['node_modules', '.git'],
'signing' => ['enabled' => env('SCALPEL_SIGNING_ENABLED', false)],Understanding findings
Review the file path, line, scanner, and severity together. Treat CRITICAL findings as an incident signal and preserve the JSON output for investigation.
Security model
Scalpel is a detection layer running inside the application workspace. Run it from a protected cron or CI context, use a distinct user where possible, and enable HMAC signing when reports cross a trust boundary.