๐Ÿ”ด Now in Beta โ€” Try it free on your Laravel project

Hostile Adversarial Vulnerability & Oversight Check

Break your code before attackers do.

Framework-aware security scanning that finds real vulnerabilities โ€” not generic noise. Understands your Laravel policies, Gates, and Eloquent scoping. Runs on every PR.

0.7s Full scan, 1,084-file app1
15 Laravel analyzers — 7 production-ready
1,296 Tests, green on every commit

1 Measured on Koel at pinned commit 41cab99 โ€” 1,084 PHP files, 649–813 ms across three runs. Analysis time only; excludes clone and dependency install. Reproduce it: npx @havoc-security/cli scan and read metadata.durationMs.

bash โ€” ~/projects/demo-app
โฏ havoc scan

Not another generic scanner.

Generic tools flag hundreds of phantom issues. HAVOC understands your framework's security model and finds gaps that actually matter.

๐Ÿง 

Framework-Aware

Understands Laravel policies, Gates, middleware, and Eloquent scoping. Not just regex โ€” real AST analysis of your framework's security model.

๐Ÿ“Š

Authorization Coverage

Track what % of your endpoints have security checks โ€” like code coverage, but for auth. Trending over time so you can see progress.

โšก

Exploit Test Generation

Auto-generates PHPUnit tests that prove vulnerabilities exist. These tests become your regression suite โ€” not just findings.

๐Ÿ’ฌ

PR Comments

Inline findings on the exact lines that need attention, just like Codecov. Coverage delta in every PR description.

๐Ÿค–

AI Triage

Send any finding to an LLM for a second opinion. You get a classification — true positive, false positive, or needs review — with a confidence score and written reasoning, so you can see the argument rather than just a verdict.

๐Ÿ”ง

Auto-Fix PRs

One-click fix generation for common security patterns. HAVOC opens the PR, you review and merge.

How it works.

Step 01

Install the CLI

One command gets you scanning. Works with npm, Composer, or as a standalone binary. Zero config required to get your first results.

npm Composer Binary GitHub Action
bash
โฏ npm install -g @havoc-security/cli
added 1 package in 2.4s
โฏ havoc --version
havoc v1.0.0
bash โ€” ~/projects/demo-app
โฏ havoc scan
Detecting framework... Laravel 12.x โœ“
Running 15 analyzers...
๐Ÿ”ด HIGH [HAVOC-001] Missing authorization gate
TransactionController.php:142
bulkConfirm() has no $this->authorize() call
๐ŸŸก MED [HAVOC-002] Unescaped Blade output
resources/views/investor/show.blade.php:23
Authorization Coverage: 132/147 (89.8%)
Scan complete in 18.4s
Step 02

Run your first scan

HAVOC auto-detects your framework and runs 15 specialized analyzers. Results in seconds, not hours. Authorization coverage calculated across every controller method.

Diff-aware in CI โ€” only scans changed files in PRs, but reports overall coverage from the last full scan.

Step 03

Fix findings. Ship confidently.

Each finding includes an explanation, a code fix, and links to OWASP/CWE documentation. Auto-fix PRs for common patterns. Exploit tests as regression suite.

View sample finding โ†’
HIGH HAVOC-001 Fixed

Missing authorization gate

TransactionController.php:142

Fix suggestion
+ $this->authorize('bulkConfirm', $project);
Generate Fix PR

Lives right in your PR workflow.

HAVOC posts inline comments on the exact lines with issues โ€” just like Codecov. Your team sees security findings in context, not buried in a separate dashboard.

H
havoc-security bot commented on this pull request just now

๐Ÿ”ด HAVOC Security Report

2 new findings in feature/bulk-transactions

FindingFileLine
HIGH Missing authorization gate TransactionController.php 142
MED Mass assignment risk Transaction.php 31

Authorization Coverage

91.8% โ†“ 2.4%
๐Ÿ”ข 2 new findings โœ… 0 CVEs ๐Ÿงช 73 exploit tests passing
Powered by HAVOC ยท View full report ยท Configure

Start free. Scale as you grow.

No credit card required to start. Upgrade when you need the cloud dashboard and advanced features.

Free
$0 forever

Full scanning power for personal and side projects. No credit card. No trial. No catch.

1 repository
CLI + GitHub Action
All 15 framework analyzers
Authorization coverage report
PR inline comments + status checks
Unlimited local scans
Cloud dashboard & history
AI triage & auto-fix PRs
Team collaboration
Get Started Free
Best for Indie Devs
Solo
$29/month

For independent developers who need full scanning power.

5 repositories
50 scans / month
15 framework analyzers
Cloud dashboard
Scan history & trends
PR inline comments
1 user
AI triage
Auto-fix PRs
Get Started
Business
$499/month

Unlimited scale with enterprise-grade controls.

Unlimited repositories
Unlimited scans
Everything in Team
Unlimited AI features
Custom webhooks
Priority support
SSO (coming soon)
50 users
Get Started
Enterprise
Custom

Self-hosted, SLA, audit logs, and dedicated security support.

Everything in Business
Self-hosted scanner
SSO / SAML
Dedicated support
99.9% SLA
Audit logs
Custom integrations
Unlimited users
Contact Sales

Free tier is real scanning โ€” not a teaser.

The CLI and GitHub Action run all 15 analyzers, generate authorization coverage reports, and post inline PR comments โ€” completely free. No account required for local scans.

โœ… Free โ€” always

  • โ€ข All 15 analyzers
  • โ€ข Authorization coverage
  • โ€ข PR inline comments
  • โ€ข Exploit test generation
  • โ€ข CI/CD integration

๐Ÿ”“ Paid โ€” adds

  • โ€ข Cloud dashboard & trends
  • โ€ข On-demand AI triage
  • โ€ข One-click auto-fix PRs
  • โ€ข Team sharing & alerts
  • โ€ข Multi-repo management

Frequently asked questions.

Snyk and Semgrep are generic tools โ€” they treat all code the same. HAVOC is built around your framework's security model. It knows that a missing $this->authorize() in a Laravel controller is a real vulnerability, not a suggestion. This framework-awareness means fewer false positives and more real findings.

No. Code is cloned for scanning and deleted immediately after. We store scan results (findings, coverage metrics, metadata) โ€” never your source code. Enterprise customers can use the self-hosted scanner, which means your code never leaves your network.

HAVOC supports Laravel (PHP). All 15 analyzers are Laravel-specific: authorization coverage, mass assignment, XSS surfaces, SQL injection, IDOR, privilege escalation, credential exposure, session security, file uploads, rate limiting, encryption at rest, insecure deserialization, open redirects, security headers, and dependency auditing. Symfony, Rails and Django are not supported today — HAVOC declines to scan them rather than apply Laravel rules to code they do not fit.

HAVOC parses every public controller method and checks whether it has an authorization check โ€” $this->authorize(), Gate::, can(), or middleware on the route. It reports a percentage (e.g. "94.2% of 147 methods") and which specific methods are missing checks. Think of it like code coverage, but for security.

Yes! The CLI and GitHub Action are completely free and don't require a HAVOC Cloud account. You get terminal output, PR comments, and commit status checks. The cloud dashboard adds history, trends, team features, and AI-powered enhancements on top.

All paid plan features are available free for 14 days โ€” no credit card required. After the trial, you can stay on the Free tier or subscribe to a paid plan. We don't lock you out or hold your scan history hostage.