darvis / livewire-injection-stopper
Blocks spam bots and Livewire payload injection in Laravel apps, keeps the resulting Livewire exceptions out of Sentry, and audits Livewire components for unlocked public properties.
Package info
github.com/ArvidDeJong/livewire-injection-stopper
pkg:composer/darvis/livewire-injection-stopper
Requires
- php: ^8.2
- laravel/framework: ^11.0|^12.0|^13.0
- livewire/livewire: ^3.0|^4.0
Requires (Dev)
- larastan/larastan: ^3.0
- laravel/pint: ^1.0
- orchestra/testbench: ^9.0|^10.0|^11.0
- pestphp/pest: ^3.0|^4.0
- pestphp/pest-plugin-laravel: ^3.0|^4.0
- phpunit/phpunit: ^11.0|^12.0|^13.0
Suggests
None
Provides
None
Conflicts
None
Replaces
None
README
A Laravel package for applications that use Livewire. Its middleware rejects requests from listed User-Agents and IP addresses, and Livewire update requests that send an array to a property that should hold a single value. It also keeps two bot-driven Livewire exceptions out of your error tracker, and its audit command lists public Livewire properties that probably need #[Locked].
Features
- Rejects a request whose User-Agent contains a listed pattern (
python,curl/,wget,go-http-client,axios, named SEO and AI crawlers and more), with an allow list for uptime monitors. The default list holds no search engine. - Rejects the exact IP addresses you list, and skips every check on the paths you whitelist, such as webhooks
- Inspects Livewire update requests and rejects an array sent to a property that looks scalar; by default that is every top-level property
- Answers
CannotUpdateLockedPropertyExceptionand theTypeErrorfrom a Livewire array assignment with the block response, and keeps them out of Laravel's exception reporting php artisan livewire-injection-stopper:auditlists public properties that probably need#[Locked], with exit code 1 for CI- A
RequestBlockedevent and a log line for every blocked request - A Laravel Boost guideline and skill
It is not a firewall: a bot that sends a browser User-Agent passes, and scalar values are never inspected. See what it does not stop.
Requirements
PHP 8.2+, Laravel 11, 12 or 13, and Livewire 3 or 4.
Installation
composer require darvis/livewire-injection-stopper
Nothing else is needed. The middleware joins the web group, the exception handling registers itself, and the audit command is available. To change a default, publish the config:
php artisan vendor:publish --tag=livewire-injection-stopper-config
One default to know before you install: every array sent to a top-level Livewire property is rejected. A multi-select bound with wire:model="tags" needs a nested key such as form.tags, or block_all_array_injections set to false. See Payload injection.
Quick start
Run the audit:
php artisan livewire-injection-stopper:audit
[CRITICAL]
📍 app/Livewire/Checkout.php:10
Property: $isAdmin (bool)
💡 Add #[Locked] attribute above this property
Lock the property it names:
<?php // app/Livewire/Checkout.php namespace App\Livewire; use Livewire\Attributes\Locked; use Livewire\Component; class Checkout extends Component { #[Locked] public bool $isAdmin = false; }
A request that tries to change isAdmin now gets 403 Access Denied, a log line that starts with [LivewireInjectionStopper] and a RequestBlocked event, and the exception Livewire throws is not reported. The Quick start page has the complete example, including a listener that counts blocked requests.
Documentation
Full documentation at arviddejong.github.io/livewire-injection-stopper:
- Installation: the steps, and how to check that it works
- Quick start: audit, lock a property and count blocked requests
- How it works: the four checks in order, and what the package does not stop
- Bot blocking: User-Agents, IP addresses, whitelisted paths, the response, the log line and the event
- Payload injection: the payload rules and the two silenced exceptions
- Security audit: what the audit scans, its output and its limits
- Configuration: every key with its default
- Testing: a complete feature test for your own app
- Troubleshooting: a legitimate request is blocked, or nothing is
- FAQ: short answers
Laravel Boost
The package ships a guideline and a skill for Laravel Boost. Run php artisan boost:install, or php artisan boost:update --discover in a project that already uses Boost.
Testing
composer test # Pest composer lint # Pint, check only; composer format fixes composer analyse # Larastan, level 8
Changelog
See CHANGELOG.md.
Contributing
See CONTRIBUTING.md.
Security
Found a way around the bot blocking or the payload inspection? Please report it privately; see SECURITY.md.