Any tier · 23 specialized tests

Filament (Laravel Admin) Security

Livewire CSRF, property hydration, Filament Resources authz, multi-tenancy bypass

What Gets Tested

Livewire CSRF / property hydration bypass (CVE-2024-47823)
Livewire public-method invocation enumeration
Livewire snapshot-checksum tampering
Filament Actions unsigned-URL bypass
Filament Resources authz matrix (per-model CRUD)
Multi-tenancy bypass (cross-tenant data leak)
Tables SQLi via raw whereRaw filters
Forms mass-assignment probes
Notifications stored XSS
Spatie Permissions middleware-order bypass
Broadcast channel eavesdrop (Pusher/Reverb)
Livewire DoS via property-heavy component

How It Works

1

Detection

Match Livewire + Alpine + Filament CSS classes; confirm /livewire/update endpoint.

2

Livewire Attacks

Snapshot manipulation, checksum tampering, public-method invocation, file-upload TTL.

3

Filament Layer

Resources authz matrix, Tables SQLi, Forms mass-assignment, multi-tenant bypass.

4

Baseline

Laravel APP_KEY / Ignition / Telescope / Horizon / Debugbar re-checked under Filament context.

Compliance Coverage

OWASP-A01 (Broken Access Control) OWASP-A07 (Auth Failures) WSTG-SESS-05

Filament (Laravel Admin) Security

€109

Any tier · One-time per scan

23 specialized tests + AI-powered analysis

Start Your Scan

Select this addon when configuring your scan

Related Add-Ons