Laravel Vet: Review Composer Code Before It Installs
Laravel Vet is a Composer plugin that analyzes third-party package dependencies for supply chain risks, malicious scripts, and CVE vulnerabilities prior to package installation.
Supply Chain Security with Laravel Vet
Open-source dependencies power modern web development, but supply chain attacks and package account takeovers have become increasingly sophisticated. Laravel Vet is an automated security gatekeeper that vets every Composer package before it touches your disk.
Pre-Installation Protection
Traditional security checkers run after packages have already been extracted and post-install hooks have executed. Laravel Vet intercepts Composer execution during resolution:
- Script Hook Verification: Warns when a package attempts to execute arbitrary shell scripts or downloads binaries in
post-autoload-dumphooks. - Maintainer Reputation Checks: Flags freshly published package versions or sudden ownership reassignments.
- CVE & Advisory Database Audits: Correlates dependencies with the FriendsOfPHP and GitHub Security Advisory databases.
# Install Laravel Vet globally
composer global require laravel/vet
# Run safe package installation
composer require vendor/cool-package
# [VETTING] vendor/cool-package (v1.2.0)
# ✓ Maintainer verified: JohnDoe (5 yrs active)
# ✓ Zero reported CVEs
# ✓ No suspicious install lifecycle hooks
# [STATUS] Package approved for installation.