Download the PHP package 1gbits/hostdoctor-laravel without Composer
On this page you can find all versions of the php package 1gbits/hostdoctor-laravel. It is possible to download/install these versions without Composer. Possible dependencies are resolved automatically.
Download 1gbits/hostdoctor-laravel
More information about 1gbits/hostdoctor-laravel
Files in 1gbits/hostdoctor-laravel
Package hostdoctor-laravel
Short Description Health checks for hosts, servers and web services in Laravel. HTTP, TLS, TCP, DNS, security headers and a normalized health score.
License MIT
Homepage https://github.com/1gbitsofficial/hostdoctor-laravel
Informations about the package hostdoctor-laravel
HostDoctor for Laravel
Diagnose hosts, servers and web services from your Laravel app — in one call.
HTTP • TLS • TCP • DNS • Security headers • Health score
HostDoctor is an SDK, not a monitoring SaaS: your application calls it right now, and gets back a normalized, machine-readable report — the same schema this package will share with future HostDoctor SDKs in other languages.
Requirements
- PHP 8.0+ with
curl,opensslandjsonextensions - Laravel 8, 9, 10, 11 or 12
Installation
The service provider and the HostDoctor facade are auto-discovered. To customize configuration:
Quick start
Targets can be a URL, hostname, IP, or host:port:
Options
The individual doctors
Every doctor validates the target against safe mode first, then returns a plain array.
HTTP
Redirects
TLS
TCP ports
Network (DNS / dual stack)
Security headers
HostDoctor reports observable configuration — it never claims a site is "secure", and it is not a vulnerability scanner.
Artisan commands
Exit codes (CI-friendly)
| Code | Meaning |
|---|---|
0 |
healthy |
1 |
warning |
2 |
degraded / critical (for tls/port: check failed) |
3 |
internal error (invalid target, blocked by safe mode, ...) |
Use it as a deploy gate:
The report schema
Every full check returns the same shape (schema version 1.0):
Issue codes
Codes are stable and machine-readable — branch on code, never on message.
| Code | Severity | Meaning |
|---|---|---|
DNS_RESOLUTION_FAILED |
critical | host has no A/AAAA records |
CONNECTION_REFUSED |
critical | primary TCP port closed |
CONNECTION_TIMEOUT |
critical | TCP/HTTP connection timed out |
HTTP_UNREACHABLE |
critical | HTTP request failed |
HTTP_UNEXPECTED_STATUS |
critical/warning | error status, or mismatch with expected_status |
HTTP_TOO_SLOW |
warning | response time above threshold |
REDIRECT_LOOP |
critical | redirect chain loops |
TOO_MANY_REDIRECTS |
warning | no final response within max_redirects |
TARGET_BLOCKED |
warning | redirect to a safe-mode-blocked target was not followed |
TLS_UNAVAILABLE |
critical | TLS handshake impossible |
TLS_INVALID |
critical | certificate not trusted |
TLS_EXPIRED |
critical | certificate expired |
TLS_EXPIRING_SOON |
warning | expires within tls.expiry_warning_days |
TLS_HOSTNAME_MISMATCH |
critical | certificate does not match hostname |
IPV6_UNAVAILABLE |
info | no AAAA records |
SECURITY_HEADER_MISSING |
warning/info | a well-known security header is absent |
Health score
The score starts at 100; each issue deducts configurable points (see config/hostdoctor.php → scoring). Missing security headers are capped at 10 points in total.
| Score | Status |
|---|---|
| 90–100 | healthy |
| 75–89 | warning |
| 50–74 | degraded |
| 0–49 | critical |
A report with any critical issue is never reported better than degraded, regardless of score.
Safe mode (SSRF protection) — on by default
HostDoctor opens connections to arbitrary targets, so it ships with safe_mode = true:
- targets that are — or resolve to — loopback, link-local (including cloud metadata
169.254.169.254), private, CGNAT, multicast or otherwise reserved addresses are rejected with aBlockedTargetException; - every redirect hop is re-validated, so a public URL cannot bounce the probe into your internal network;
- in safe mode, connections are pinned to the validated IP to resist DNS-rebinding tricks;
localhost,*.localhost,*.localand*.internalhostnames are always rejected.
Only disable it for trusted, internal tooling:
Other protections that are always on:
- response bodies are capped (
http.max_body_bytes, default 64 KB) — HostDoctor never downloads a 10 GB file to check a status code; - request headers such as
Authorizationare redacted ([REDACTED]) anywhere they appear in a report; - timeouts apply to every probe; only timeouts are retried (
retries, default 1) — an invalid certificate is never retried.
Use cases
Post-provisioning check — mark a VPS ready once SSH answers:
Deploy gate — fail the pipeline when production is unhealthy:
Support triage — ask the customer for a machine-readable report:
Testing your own code
HostDoctor is resolved from the container (hostdoctor / HostDoctor::class), and every probe sits behind a contract (OneGbits\HostDoctor\Contracts\*), so you can swap the whole service or individual probes:
The package's own suite (98 tests) runs fully offline this way.
Roadmap
- 1.1 — batch checks, config-file/CI mode, JSON body expectations, richer retry policies
- 1.2 — probes for SSH banners, SMTP, MySQL/PostgreSQL, Redis, WebSocket
- 2.0 — plugin system for community probes
License
MIT © 1Gbits
All versions of hostdoctor-laravel with dependencies
ext-curl Version *
ext-json Version *
ext-openssl Version *
illuminate/console Version ^8.0|^9.0|^10.0|^11.0|^12.0
illuminate/support Version ^8.0|^9.0|^10.0|^11.0|^12.0