TECHNOLOGIES: LARAVEL LIVEWIRE

Laravel Livewire Penetration Testing

A Livewire component’s public properties are sent to the browser and back, open to tampering unless you guard them. We test those properties, its actions, file uploads and their authorisation. CREST-certified testers, fixed price from £2,560 for a 2-day single-application scope, quoted within 24 hours.

  • Unlimited retesting
  • Unlimited pre-retesting
  • No hidden fees
Accredited & recognised
Cyber Essentials certified Cyber Essentials Plus certified IASME certifying body ISO 27001 certified ISO 9001 certified Crown Commercial Service supplier UK Cyber Security Council member
CREST
Approved Provider
10
Laravel Livewire Test Areas
FREE
Retest Until Closed
24h
Scope to Active Test
CLIENT REFERENCE
“I would highly recommend EJN Labs to any organisation seeking reliable, detailed, and well-managed penetration testing services, particularly for government or enterprise-level projects.”
SquareOneImran SaghirProject Lead, SquareOneRead the SquareOne case study →
CLIENT REFERENCE
“There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.”
CelloriDan WilcocksonFounder, CelloriRead the Cellori case study →
See all case studies →
WHY IT MATTERS
Public

Livewire’s own documentation says every public property is dehydrated into JSON and sent to the browser between requests, exposing its value and, for an Eloquent model, its class name unless a morphMap alias hides it.

Why a Livewire property or action parameter is only as safe as what you check on the server

Livewire’s own Properties documentation is explicit that a public property is serialised, or dehydrated, before every round trip to the browser, and for a property holding an Eloquent model that dehydrated value includes the model’s class name, its key and any eager-loaded relationships, unless a morphMap alias is set up to hide the class name. The #[Locked] attribute stops a property being changed from the browser, though Livewire’s documentation notes a locked property can still be reassigned from your own component code, so nothing about the attribute protects against untrusted input reaching it from inside a method.

Livewire’s Security documentation treats any parameter passed to an action as mutable on the client and therefore untrusted, since a user can rewrite the markup calling that action in the browser to submit a different value than the one it was rendered with; the same applies to a property populated through wire:model rather than passed as a parameter. Its own worked example shows deleting a record by an unauthorised ID as insecure for exactly this reason, and recommends either typing the property as the Eloquent model itself, which Livewire will not let a client swap for a different record, or calling $this->authorize() inside the action before anything is persisted.

Persistent middleware is Livewire’s mechanism for re-checking authorisation on every subsequent request rather than only the first page load, and it only reapplies the specific middleware classes Livewire already knows about, Sanctum’s EnsureFrontendRequestsAreStateful and Laravel’s own Authenticate and Authorize among them, unless a custom middleware is registered separately through Livewire::addPersistentMiddleware(). Every request also carries a checksum of the component’s snapshot, and a mismatch throws a CorruptComponentPayloadException rather than accepting the tampered payload, the same discipline our PHP and Laravel penetration testing applies to the routes, controllers and policies sitting underneath every Livewire component.

SCOPE

What we pen test on a Laravel Livewire application

LW-01

Public Properties Are Serialised to the Browser

Every public property on a Livewire component is dehydrated to JSON and sent to the browser between requests, and for a property holding an Eloquent model that payload includes the model’s class name, its key and any eager-loaded relationships unless a morphMap alias hides the class name. We test what every public property actually exposes once dehydrated, since removing a value from the rendered page does not remove it from the payload behind it.

LW-02

The #[Locked] Attribute and Model-Typed Properties

The #[Locked] attribute throws an error if a user tries to change a property from the browser, but Livewire’s own documentation notes a locked property can still be changed from your own component code, so it protects against client tampering only; typing a property as an Eloquent model instead means Livewire will not let the client substitute a different record for it at all. We test which properties rely on #[Locked], which rely on a model type, and whether either still lets an authorisation check be skipped.

LW-03

Action Parameters Are Untrusted Client Input

Any parameter passed to a Livewire action is mutable in the browser before the request is sent, and Livewire’s own worked example shows that deleting a record by that parameter without an authorisation check lets a user delete a record they never should have reached. We test every action that accepts a parameter for whether the value is authorised against the signed-in user before anything is read, written or deleted.

LW-04

Authorising Public Properties Instead of Action Parameters

Storing a record’s ID as a public property rather than passing it as an action parameter does not make it safer, since Livewire’s documentation shows the same property can be overwritten by an injected wire:model bound input, letting a user redirect an action such as delete() at a different record entirely. We test whether a component’s public properties are authorised the same way its action parameters are, not assumed safe because they arrived from mount() rather than a click.

LW-05

Persistent Middleware and What It Actually Reapplies

Livewire reapplies only a fixed list of middleware classes on every subsequent request after the first page load, including Sanctum’s EnsureFrontendRequestsAreStateful and Laravel’s own Authenticate and Authorize, and a custom authorisation middleware from your own application has to be registered separately with Livewire::addPersistentMiddleware() or it runs on the initial load only. We test whether every middleware your routes rely on for authorisation is actually on that persistent list, since one left off stops protecting a component after the page has loaded.

LW-06

Snapshot Checksums and Tampered Requests

Every request carries a checksum of the component’s last snapshot, and Livewire throws a CorruptComponentPayloadException rather than processing the request if that checksum does not match, documented as protection against a fetch request being intercepted and modified in the browser. We test what a modified snapshot or checksum is actually rejected for, and whether any component state still leaks into the error response Livewire returns when it fails that check.

LW-07

Temporary File Storage: Your Server or Direct to S3

A file uploaded through WithFileUploads lands in a livewire-tmp/ directory on your application’s default filesystem disk by default, meaning every upload passes through your own server first, unless LIVEWIRE_TEMPORARY_FILE_UPLOAD_DISK is set to s3, or another disk using the s3 driver, to send it straight to that bucket instead. We test where uploads actually land, what the livewire-tmp/ directory or its S3 equivalent allows once a file is there, and how long a temporary file survives if it is never claimed.

LW-08

Temporary Preview URLs Are Restricted to Images

The temporaryUrl() method Livewire provides for showing an upload before it is saved only works on files with an image MIME type, and Livewire’s documentation describes the URL as signed and protected against reaching a file outside the temporary directory it was issued for. We test what temporaryUrl() actually returns for a non-image file, and whether the signed URL’s protection against directory traversal holds once a filename is manipulated.

LW-09

Server-Side Validation via #[Validate] Still Runs on Every Request

A rule such as #[Validate(‘image|max:1024’)] attached to a property is enforced on the server on every request that submits it, not just the file input’s own client-side constraints, which is what stops a renamed or oversized file from ever reaching your storage disk. We test what happens when a validated property is submitted outside the constraints its client-side input implies, since the browser’s file picker is not what actually enforces the rule.

LW-10

The Wider Laravel Application Around Livewire

A Livewire component sits inside a full Laravel application, with its own routes, controllers, policies and database migrations outside anything Livewire itself renders. Where that wider application is in scope alongside its Livewire components, our PHP and Laravel penetration testing covers the rest of it.

OUR PROCESS

Laravel Livewire Penetration Testing: From Scope to Attestation

01

Scope and Access

We agree the components, routes and accounts for every role your application’s policies and persistent middleware distinguish between, plus whether file uploads go to your own server or direct to S3.

02

Property and Action Mapping

We map every public property, its dehydrated payload, and every action’s parameters against the authorisation each one actually needs.

03

Manual Testing

A CREST-certified tester manually tests property tampering, action authorisation, file upload handling and the persistent middleware protecting each component.

04

Reporting and Retest

You get a technical report with CVSS scores and reproduction steps, a walkthrough call, a free retest once fixes are deployed, and an attestation letter for auditors.

CREDENTIALS

Verified Accreditations Auditors Accept

Every credential below is independently verifiable. UK procurement teams, FCA supervisors, ISO 27001 / SOC 2 auditors, and cyber insurance underwriters all recognise these standards.

GET YOUR QUOTE

Get a CREST Laravel Livewire pen test quote in 24 hours

A fixed-price quote back in one business day, from a named CREST assessor. No sales pipeline, no chasing.

  • CREST and IASME accredited. Testing your auditors and clients already recognise.
  • Fast-track testing within 24 hours where required. Free retest of every fix included.
  • Live findings via your client portal, not a four-week PDF.
  • Fixed price from £3,500 for a single-role, single-app scope, agreed up front. Most engagements run £5,000 and up. No day-rate surprises.
What clients say
There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.
CelloriDan WilcocksonFounder, Cellori

Under NDA Further named references available on a scoping call.

What happens next
  1. We reply within one business day with a fixed-price quote from a named CREST assessor.
  2. You approve the scope and we book a start date, usually within 24 hours.
  3. Live findings land in your client portal as we test, with a free retest of every fix.
Accredited & recognised
CREST member Cyber Essentials certified Cyber Essentials Plus certified IASME certifying body ISO 27001 certified ISO 9001 certified UK Cyber Security Council Crown Commercial Service supplier

Get your fixed pen test quote in 24 hours

⚡24h reply ✓CREST tester ↻Free retests

or book a 20-min scoping call first

We reply within one business day. Your data stays with us. No newsletter signup.

COMPLIANCE READY

Reports Mapped to Every Framework

Findings are written so your team can reference the report against each framework without translation work.

ISO 27001:2022

Annex A.8.8 management of technical vulnerabilities plus A.5.15-5.18 and A.8.2-8.5 access control validation.

SOC 2 Type I & II

CC6 logical access, CC7 system operations, CC8 change management evidence.

PCI DSS

Requirement 11.4 application penetration testing across cardholder data environments, including ecommerce penetration testing for online retail platforms.

FCA SYSC

SYSC 4.1.1R, 6.1.1R, 13 mapped to each finding for FCA-regulated firms.

UK GDPR

Article 32 effectiveness testing, customer-data security controls, ICO-acceptable evidence.

Cyber Essentials Plus

Direct certification through our IASME body status, single-vendor delivery.

PRICING

Transparent Laravel Livewire Penetration Testing Pricing

Pricing depends on the number of roles, integrations and environments in scope. See our pricing page for how we quote.

✦ ALWAYS · ON EVERY TIER · NO EXCEPTIONS ✦
✓Free retests, no time limit
✓Free rescheduling
✓No cancellation fees
✓24-hour scope to active testing
✓Live findings to client portal
✓Executive + technical report
✓60-min walkthrough call
✓Letter of attestation
SMALL / SMB
£2,560–£3,840
2 to 3 testing days

Single user role, basic CRUD application, marketing website with auth. Around 5 working days from kickoff to report.

Get a fixed quote
ENTERPRISE
£6,050–£9,270
5 to 7 testing days

Multi-tenant platform, complex authorisation matrix, integration-heavy applications. Around 15 to 20 working days from kickoff to report.

Get a fixed quote

Full UK pen test cost guide

WHY EJN LABS

What You Get From Laravel Livewire Penetration Testing

Six concrete differentiators competitors don’t all match.

CREST-Certified Testers, Verifiable

Every test by a CREST-certified pen tester (CRT, CCT APP, CCT INF where applicable). Verify our company status at crest-approved.org.

24-Hour Startup, Where Required

From signed scope to active testing in a single business day for incident response, audit deadlines, or regulator-driven timelines.

Live Findings, Not 4-Week PDFs

Critical issues reported during testing through your client portal. Your team remediates while testing continues.

Audit-Ready Reports

Executive summary plus full technical report with CVSS scores and explicit framework mappings (ISO 27001, SOC 2, PCI DSS, FCA SYSC).

Free Retests, Standard

Verify remediation of every finding before close-out. Letter of attestation for audit submission included. Most competitors charge £1,500-£3,000 per retest.

UK-Based CREST Testers

Every engagement performed by vetted, UK-based CREST-certified testers, matched to your needs, security clearance, and compliance scope.

FAQ

Frequently Asked

What access do you need to test our Livewire application?

We need at least one authenticated account for every role your components and Laravel Policies distinguish between, and read access to the relevant component classes speeds up confirming what a public property or action actually authorises.

Will testing touch our live data?

We test whichever environment you give us access to. If that is production, we agree exclusions upfront, such as bulk deletes and outbound emails, and we do not run destructive tests against real customer records without that agreement in writing.

How long does a Laravel Livewire penetration test take?

A single application sits in our 2-day single-application scope, with a report typically landing around 5 working days after kickoff. An application with a large number of components, file uploads or a wide persistent middleware list moves into a larger scope.

Do you test the Laravel application behind our Livewire components, or just the components themselves?

Both, where they’re in scope together. Livewire components sit inside a full Laravel application, and issues in the routes, controllers or policies underneath a component are tested alongside the component’s own properties and actions.

What is out of scope for a single-application Livewire test?

Infrastructure-level issues in the underlying server, network or cloud configuration are out of scope and covered by our cloud penetration testing service instead. A separate frontend framework consuming the same backend independently of Livewire is also scoped and quoted separately.

Do you need our source code?

No. Testing is black-box against the running application by default. A grey-box option, where we review the relevant component classes, policies and middleware configuration alongside testing, is available if you want faster or deeper coverage of specific findings.

Does Livewire have a customer penetration-testing policy we need to follow?

Livewire runs as part of your own Laravel application rather than a shared multi-tenant service. We confirm Livewire’s and your hosting provider’s current terms during scoping before testing begins.

EXPLORE EVERY SERVICE

20+ CREST-accredited testing services in one place

Web, mobile, API, cloud, AI, infrastructure, red team. Pick the test that fits your environment.

Penetration testing services
READY TO START

Get a fixed price for your Laravel Livewire application

A Livewire component’s public properties are sent to the browser and back, open to tampering unless you guard them. We test those properties, its actions, file uploads and their authorisation. CREST-certified testers, fixed price from £2,560 for a 2-day single-application scope, quoted within 24 hours.