Be part of JetBrains PHPverse 2026 on June 9 – a free online event bringing PHP devs worldwide together.

Fahad Pervez's avatar

VeraCode Vulnerability Scanner Bugs in Laravel Vendor

Hi Laravel Experts,

I wanted to discuss with you guys that our company is using Veracode Scanner before uploading the laravel code to the server.

Problem we are facing is that the scanner is finding most of the vulnerabilities in the Vendor file, that is it self the laravel framework code in which it is built.

Our criteria is that it should avoid vendor code vulnerabilities.

Anyone with the experience how to avoid laravel vendor code in veracode scanner.

Any help will be appreciated.

Thanks,

0 likes
6 replies
bobbybouwmann's avatar

Veracode scanner seems to be very outdated and looking a the forum I couldn't really find an answer. They basically say that the vendor directory should be fixed by yourself 😅 Also it doesn't seem they have first-party support for Laravel. If they would, there wouldn't be an issue at all

Anyway, I don't think I can help you other then recommending you to use a different tool

1 like
Fahad Pervez's avatar

@bobbybouwmann Thank you bobby :) , Really appreciate your help. Can you suggest us other tools other than veracode, so we can look into it. ?

Snapey's avatar

@Fahad Pervez apparently the next version of composer is checking for packages with known vulnerabilities

1 like

Please or to participate in this conversation.