captainhook/secrets
Detect secrets like passwords and API keys in code to prevent accidental commits. Use built-in regex suppliers (AWS, Google, GitHub, etc.) or provide your own patterns, plus a whitelist for allowed matches. Includes a simple Detector API.
Executives: "This package eliminates a critical attack vector—accidental secret commits—by automatically blocking credentials like API keys and passwords before they reach production. It prevents costly data breaches, regulatory fines, and reputational damage while requiring zero ongoing maintenance. A low-risk, high-impact security control that integrates seamlessly into existing workflows."
Engineering: "A lightweight, MIT-licensed PHP package with pre-configured detectors for major cloud providers and customizable regex rules. Integrate it in <5 minutes via Git hooks or CI pipelines—no dependencies beyond PHP 8
How can I help you explore Laravel packages today?