Weave Code
Code Weaver
Helps Laravel developers discover, compare, and choose open-source packages. See popularity, security, maintainers, and scores at a glance to make better decisions.
Feedback
Share your thoughts, report bugs, or suggest improvements.
Subject
Message

Plugin Laravel Laravel Package

psalm/plugin-laravel

Laravel Psalm plugin for deep static analysis plus taint-based security scanning. Detects SQL injection, XSS, SSRF, shell injection, path traversal, and open redirects by tracking user input through Laravel code without running it.

View on GitHub
Deep Wiki
Context7

title: NoEnvOutsideConfig parent: Custom Issues nav_order: 1

NoEnvOutsideConfig

Emitted when env() is called outside the application's config directory (by default the booted app's config_path(); configurable via <configDirectory> for non-standard layouts).

Why this is a problem

When you run php artisan config:cache, Laravel loads all config files once and caches the result. After that, the .env file is not loaded — so any env() call outside config/ returns null.

This is a documented Laravel behavior:

You should be confident that you are only calling the env function from within your configuration files. [...] If you cache your configuration, the env function will only return null.

Examples

// Bad — will return null when config is cached
class PaymentService
{
    public function getKey(): string
    {
        return env('STRIPE_SECRET'); // NoEnvOutsideConfig
    }
}
// Good — read env in config, use config() elsewhere

// config/services.php
return [
    'stripe' => [
        'secret' => env('STRIPE_SECRET'),
    ],
];

// app/Services/PaymentService.php
class PaymentService
{
    public function getKey(): string
    {
        return config('services.stripe.secret');
    }
}

How to fix

  1. Move the env() call into a config file (e.g. config/services.php)
  2. Reference the value via config() in your application code

Custom config directories

By default the plugin treats only the Laravel app's config_path() as a config directory. If your project keeps configuration elsewhere (for example BookStack's app/Config/) or you want to allow env() inside vendor packages, add <configDirectory> elements to your psalm.xml:

<pluginClass class="Psalm\LaravelPlugin\Plugin">
    <configDirectory name="app/Config" />
    <configDirectory name="packages/*/config" />
</pluginClass>

See Configuration for the full reference.

Weaver

How can I help you explore Laravel packages today?

Conversation history is not saved when not logged in.
Prompt
Add packages to context
No packages found.
codraw/graphviz
nexmo/api-specification
capell-app/block-library
axium/identity
cetria/laravel-dummy-models
cetria/reflection-helper
agropredict/sso-auth-bundle
evolvestudio/spam-protection
datacore/hub-sdk
develia/commons
cuci/prototurk-sdk
cuci/prototurk-sdk-symfony
develia/geo-bundle
dreamzy/livewire-charts
touchestate-sdk/php-sdk
22h/doctrine-garbage-collection-bundle
agtp/agtp-php
agtp/mod-php
splash/sonata-admin
splash/metadata