Fillable Foreign Key
Your application does not expose foreign keys for mass assignment.
- Severity
- Critical
- Typical fix
- ~10 minutes
- Analyzer
- FillableForeignKeyAnalyzer
What it checks
A focused signal for security risk.
Your application does not expose foreign keys for mass assignment. LaraBeacon evaluates the relevant Laravel code, configuration, dependency, or runtime boundary and reports the concrete location whenever the analyzer can identify one.
Recommended response
Fix the cause, then lock in the decision.
Treat the finding as a security boundary: remove untrusted input from the sensitive operation and add a regression test for the protected path.
If the behavior is intentional, document the decision through LaraBeacon’s baseline or analyzer configuration instead of silently ignoring the result in a release pipeline.
Availability
Included in the open-source Core.
This analyzer ships with LaraBeacon Core and can run locally or in CI without a LaraBeacon account.