fruitcake/laravel-debugbar
66.3
Adequate · 25 September 2026
6.5k
lines of production code
PHP
with JavaScript
4
measurements over time
What this system is
This system is a modernized Laravel debugging package that provides comprehensive visibility into application performance and state. It collects and stores detailed metrics from database queries, HTTP clients, views, and modern Laravel features like Livewire and Inertia, while offering tools to analyze SQL performance and manage cached data. The package supports persistent storage, CLI inspection, and integration with external debugging tools like Clockwork and Laravel Octane.
How it got here
2013–2014 — Fruitcake rebrand and Laravel 11 support
11 changes.
The project underwent a major rebrand from Barryvdh to Fruitcake, upgrading to support Laravel 11-13 and PHP 8.2+ while dropping legacy versions. This period introduced extensive new collectors for modern Laravel features like Octane, Livewire, and AI, alongside comprehensive CLI tools for storage inspection and a complete overhaul of development tooling and test coverage.
2015–2021 — Feature expansion and test coverage
9 changes.
This period focused on expanding the Laravel Debugbar's capabilities by adding Clockwork integration, database storage, and middleware controls for visibility and performance. Comprehensive unit tests were introduced to verify data collection accuracy across various collectors and formatters, ensuring robust handling of edge cases and complex data structures.
2024–2026 — UI modernization and Octane stability
11 changes.
This period focused on modernizing the Debugbar interface with CSS variables, dark mode support, and Tabler Icons, while introducing new features like visual query analysis and cache management widgets. Significant backend work included refactoring collector providers for better maintainability and implementing strict request validation to enhance security. The release also prioritized stability for long-running processes by fixing state leakage in Laravel Octane and expanding test coverage across controllers, console commands, and Livewire components.
Features
Add Clockwork data collector and converter for phpdebugbar output
This change introduces a new Clockwork integration within the Laravel Debugbar support layer. The \ClockworkCollector\ now gathers request, response, session, and header data (with authorization masking) from the Symfony HTTP foundation objects. Additionally, the \Converter\ class transforms internal phpdebugbar metrics—including timeline measures, route definitions, log messages, exceptions, database queries (excluding explain/info statements), model events, view rendering, Symfony Mailer emails, and event listeners—into the specific JSON structure required by the Clockwork debugging tool, enabling users to view their debug data in Clockwork's interface.
src/Support/Clockwork · high confidence
Add database migration for PHP DebugBar storage
A new database migration has been added to create the 'phpdebugbar' table, which stores debug bar data including identifiers, payloads, and metadata such as timestamps, URIs, IPs, and HTTP methods. This enables the application to persist PHP DebugBar information in the database rather than using the default file-based storage.
database · high confidence
Automated documentation build and icon generation scripts
Added build scripts to automate the generation of documentation assets and UI icons. The new \build/build-docs.php\ script updates the documentation template with debugbar scripts, copies distribution assets, and updates version timestamps in the configuration to ensure cache busting. The new \build/build-icons.js\ script generates a CSS file from Tabler Icons, converting SVGs into data URIs and applying consistent styling for both outline and filled icon variants used in the debugbar interface.
build · high confidence
Initial configuration file for Laravel Debugbar
Adds the \config/debugbar.php\ file, establishing the default settings for the Laravel Debugbar package. This configuration allows users to enable or disable specific data collectors (such as database queries, views, jobs, and HTTP client requests) via environment variables, and fine-tune collector behavior (like query backtraces, memory usage tracking, and mail body display) through the options array. It also sets the default editor for file navigation and defines URIs to exclude from collection.
config · high confidence
Introduce LaravelDebugbar Facade
A new \Debugbar\ facade has been added to the \Fruitcake\\LaravelDebugbar\\Facades\ namespace, providing a static interface to the \LaravelDebugbar\ service. This allows users to access debug bar features such as adding collectors, logging messages, and checking for existing collectors directly via the facade class.
src/Facades · high confidence
New CLI commands for inspecting and managing Debugbar storage
Added \debugbar:find\, \debugbar:get\, \debugbar:queries\, and \debugbar:clear\ commands to the console. \debugbar:find\ lists stored requests with optional filtering by time, IP, method, URI, and issue detection (high query counts, slow durations, duplicates). \debugbar:get\ retrieves a specific request's data, showing a summary or raw JSON, and supports filtering by collector. \debugbar:queries\ displays query statements for a request, highlighting duplicates, N+1 patterns, and failures, with options to run EXPLAIN or fetch results. \debugbar:clear\ removes stored debugbar data, handling missing storage locations gracefully. Also added \debugbar:install-skill\ to install AI coding agent skills for debugging.
src/Console · high confidence
New EXPLAIN output and visual query analysis support
A new Explain class has been added to the Support component to enable enhanced query debugging. It provides logic to generate raw EXPLAIN outputs for MySQL, MariaDB, and PostgreSQL, and integrates with external services (mysqlexplain.com and explain.dalibo.com) to generate visual query plans. The implementation includes safety checks to ensure only read-only (SELECT) queries are processed and verifies query integrity via hashing before execution.
src/Support · high confidence
New cache widget for Debugbar 3.x integration
A new JavaScript widget (LaravelCacheWidget) has been added to the resources/cache directory to support the upcoming Debugbar 3.x release. This widget displays cache events in the debug bar and allows users to delete specific cache keys directly from the interface via a 'forget' link, which triggers a DELETE request to the server and updates the UI upon success or failure.
resources/cache · high confidence
New collectors for AI, HTTP client, Inertia, Livewire, Pennant, and Config
This release introduces several new data collectors to the debug bar. The new AiCollector tracks Laravel AI agent activity, including prompts, responses, token usage, and tool calls. The HttpClientCollector records HTTP client requests and responses, including multipart data and connection failures. The InertiaCollector captures Inertia page components and their props, while the LivewireCollector now supports Livewire 4, correctly resolving source paths for single- and multi-file components. Additionally, the PennantCollector displays Laravel Pennant feature flags, and the ConfigCollector exposes the application's configuration. These collectors provide deeper visibility into modern Laravel application features and interactions.
src/DataCollector · high confidence
New middleware to control DebugBar visibility and Telescope recording
Two new middleware classes have been added to the Fruitcake\\LaravelDebugbar\\Middleware namespace. The DebugbarEnabled middleware allows developers to gate access to the DebugBar interface by returning a 404 error if the bar is disabled, enabling runtime enable/disable control via middleware. The StopRecordingTelescope middleware automatically stops Laravel Telescope from recording data for the current request if Telescope is installed, preventing unnecessary overhead when DebugBar is active.
fruitcake/laravel-debugbar · high confidence
Removals
Removal of PHP DebugBar and Font Awesome 3.2.1 public assets
The \public\ directory no longer includes the PHP DebugBar interface (CSS and JavaScript) or the Font Awesome 3.2.1 icon library (CSS and IE7-specific styles). These static assets have been deleted, meaning the application will no longer serve the debug toolbar UI or the associated icon styles from this location.
public · high confidence
Removal of legacy Laravel Debugbar service provider
The legacy \ServiceProvider.php\ for the \barryvdh/laravel-debugbar\ package has been removed from the codebase. This file previously handled the registration of the debug bar instance, the JavaScript renderer, and the logic to inject debug assets into HTML responses via the router's \after\ event. Its removal indicates a shift away from this specific integration method, likely requiring users to update to a newer version of the package or adopt a different mechanism for enabling the debug bar.
src/Barryvdh · high confidence
Removal of legacy configuration files
The legacy \src/config/config.php\ configuration file and the \src/config/.gitkeep\ placeholder have been removed from the project. This cleanup eliminates the previous default configuration structure that controlled settings such as enabling the debug bar based on the application debug mode and including vendor assets, indicating a shift in how configuration is managed or loaded in the current version.
src/config · high confidence
Behavioural changes
Collector providers refactored to use a common abstract base class
The collector providers in src/CollectorProviders have been restructured to extend a new AbstractCollectorProvider base class, which centralizes collector registration and exception handling. This change standardizes how collectors are added to the debug bar and ensures consistent error reporting across all providers, improving maintainability and reliability of the debugging data collection.
src/CollectorProviders · high confidence
Enhanced SQL query results and EXPLAIN visualization in Debugbar
The Laravel-specific SQL widget now provides improved interaction for query results and EXPLAIN plans. Users can view query results in a scrollable table with clickable cells to select text, and an 'Expand' button to view full details in a popup. The EXPLAIN functionality has been extended to support both MySQL and PostgreSQL drivers, displaying results in a dedicated table format. Additionally, the widget includes better handling of JSON formatting and fixes for SQLite queries, ensuring more accurate and usable output for database debugging.
resources/queries · high confidence
Fruitcake Laravel Debugbar v12 release with Octane support and new collectors
This release introduces a major architectural shift by moving the package to the Fruitcake namespace and dropping support for Laravel versions prior to 5.6, as well as removing Lumen support. It adds native compatibility with Laravel Octane by resetting the debugbar instance on each request and handling job processing events. The update includes a new cookie-based session storage mechanism to avoid session regeneration issues, a dedicated view engine for measuring view rendering times, and a suite of new collectors for AI, HTTP clients, Inertia, Livewire v3, Pennant, and Jobs. Additionally, it provides helper functions for easier access to collectors and integrates with Clockwork for request/session data.
src · high confidence
Laravel Debugbar UI refreshed with CSS variables and Tabler Icons
The Laravel Debugbar interface has been visually updated to use CSS custom properties for consistent theming, including full support for a dark mode, and has switched its icon set to Tabler Icons. This change improves readability and visual consistency across the debug bar's panels, badges, and filter buttons, while also ensuring the Laravel Whoops exception handler displays correctly above the debug bar.
resources · high confidence
New dedicated controllers for Debugbar assets, cache, queries, and Telescope integration
The Debugbar now uses dedicated controller classes (AssetController, CacheController, OpenHandlerController, QueriesController, TelescopeController) to handle its HTTP endpoints. Users can now explicitly forget cache keys via the CacheController, view detailed EXPLAIN and query results for specific statements through the QueriesController, and access Telescope request details via a new TelescopeController. The OpenHandlerController manages data retrieval with stricter storage-open checks, while the AssetController centralizes asset serving using the configured HTTP driver.
src/Controllers · high confidence
Repository modernization and tooling overhaul
The project has been modernized with a comprehensive update to its development tooling and configuration. A new \.editorconfig\ enforces consistent code style, while \pint.json\ and \eslint.config.js\ standardize formatting for PHP and JavaScript respectively. Static analysis is now handled by \phpstan.neon\ and testing by \phpunit.xml.dist\. Documentation is built using \mkdocs.yml\, and the legacy \.travis.yml\ CI configuration has been removed. Additionally, the \CHANGELOG.md\ has been introduced to track version history, and the \SECURITY.md\ policy has been added to guide vulnerability reporting.
(repo-wide) · high confidence
Reset Laravel Debugbar state on each Octane request
A new \ResetDebugbar\ event listener has been added to the Octane support layer to ensure the Laravel Debugbar is properly reset and re-initialized for every incoming request. This listener handles the \RequestReceived\ event, resetting the debugbar's application and request context, re-booting it if enabled, and correctly setting the request start time and application measurement. This prevents state leakage between requests in long-running Octane processes, ensuring accurate debugging data for each individual request.
src/Support/Octane · high confidence
Split Debug and Dump Twig extensions
The Twig integration has been refactored to separate debugging and dumping functionality into distinct extension classes. The new \Debug\ extension provides access to the debugbar's message collector within Twig templates, while the new \Dump\ extension allows variables to be dumped using the DataFormatter. Additionally, the \Stopwatch\ extension has been updated to integrate with the Laravel application container, enabling time measures to be recorded on the debugbar timeline via Twig tags.
src/Twig · high confidence
Fixes
Introduce strict form request validation for Debugbar endpoints
Added dedicated FormRequest classes (AssetRequest, CacheDeleteRequest, OpenHandlerRequest, QueriesExplainRequest) to enforce strict input validation and authorization on Debugbar routes. This change resolves issues where strict form request validation could prevent the Debugbar from loading or processing requests correctly, ensuring that parameters like asset types, cache keys, and query explain modes are validated against expected schemas before reaching the controller logic.
src/Requests · high confidence
Test coverage
Added controller tests for Debugbar routes; Added test coverage for Laravel Debugbar console commands; Added test fixtures for Livewire components; Added test model classes for Laravel Debugbar; Added test resource views for Livewire, AJAX, and query collection scenarios; Added tests for DataFormatter query binding and validation error handling; Added unit tests for DataCollector components; Comprehensive test suite for Laravel Debugbar.
Dependencies
Laravel Debugbar package rebranded and upgraded to Laravel 11-13 support
The \barryvdh/laravel-debugbar\ package has been replaced by \fruitcake/laravel-debugbar\, which now requires PHP 8.2+ and supports Laravel 11, 12, and 13. The package name change is handled via a \replace\ directive to ensure backward compatibility for existing installations. The underlying debug library has been updated to \php-debugbar/php-debugbar\ version 3.8.0, and the namespace has moved from \Barryvdh\\Debugbar\ to \Fruitcake\\LaravelDebugbar\. Additionally, a new \package.json\ and \package-lock.json\ have been added to manage frontend dependencies like ESLint and esbuild for asset building.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 44 → 66 (+21.8)
- Rubric changed (rubric-2026.08.15 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 99 → 85 (-13.9)
- Architecture 96 → 94 (-1.3)
- Maturity 55 → 55 (-0.8)
- Readiness 26 → 70 (+44.8)
- Security 48 → 78 (+30.0)
Resolved (32)
- (anonymous) (cognitive 27) (resources/cache/widget.js)
- Coverage not measured — test suite did not build
- Dimension evaluation failed
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- …and 12 more
New (75)
- (anonymous) (cognitive 31) (resources/cache/widget.js)
- (anonymous) (cognitive 44) (resources/queries/widget.js)
- (anonymous) (cyclomatic 30) (resources/queries/widget.js)
- ClassTooLong: LaravelDebugbar (src/LaravelDebugbar.php)
- Converter.convert (cognitive 57) (src/Support/Clockwork/Converter.php)
- Converter.convert (cyclomatic 33) (src/Support/Clockwork/Converter.php)
- DatabaseCollectorProvider.__invoke (cognitive 26) (src/CollectorProviders/DatabaseCollectorProvider.php)
- DatabaseCollectorProvider.__invoke (cyclomatic 25) (src/CollectorProviders/DatabaseCollectorProvider.php)
- Dependency hygiene PARTLY measured — Composer dependencies read, no committed lock to grade for currency
- Duplicated block (10 lines × 2) (src/Console/QueriesCommand.php)
- Duplicated block (13 lines × 2) (src/DataCollector/GateCollector.php)
- Duplicated block (14 lines × 3) (src/DataCollector/AiCollector.php)
- Duplicated block (15 lines × 2) (src/Console/QueriesCommand.php)
- Duplicated block (16 lines × 2) (src/DataCollector/RequestCollector.php)
- Duplicated block (17–21 lines × 2) (src/Support/Clockwork/Converter.php)
- Duplicated block (22 lines × 2) (src/Console/GetCommand.php)
- Duplicated block (28–30 lines × 2) (src/DataCollector/RequestCollector.php)
- Duplicated block (44 lines × 2) (src/DataCollector/RequestCollector.php)
- Duplicated block (5 lines × 2) (src/DataCollector/InertiaCollector.php)
- FileTooLong: src/LaravelDebugbar.php (src/LaravelDebugbar.php)
- …and 55 more
Changes since last survey
- 22 commits — 19 feature/other, 3 fixes
By area
- (root) — 10 commits
- src/DataCollector — 2 commits
- tests/DataCollector — 2 commits
- config/debugbar.php — 1 commit
- resources/cache — 1 commit
- src/CollectorProviders — 1 commit
- src/LaravelDebugbar.php — 1 commit
- src/Support — 1 commit
- tests/Console — 1 commit
- tests/Controllers — 1 commit
- tests/DebugbarBrowserTest.php — 1 commit
Notable commits
- fix: Fix AI collector compatibility with Laravel AI 1.x token usage (#2086)
- fix: Fix CS
- fix: Fix encoded route params (#2089)
- change: Add waitForText for API ping in Debugbar test (#2079)
- change: Allow laravel/ai 0.9-0.11 and test 0.11 in CI (#2090)
- change: Allow queries with comments at the beginning (#2075)
- change: Bring back view measuring (#2058)
- change: Bump @humanfs/node from 0.16.7 to 0.16.8 (#2084)
- change: Bump esbuild from 0.27.2 to 0.28.1 (#2057)
- change: Bump postcss from 8.5.15 to 8.5.25 (#2072)
- change: Clarify wording about local ips, tweak ipv6 check (#2087)
- change: Flatten ViewErrorBag/MessageBag with a caster so messages survive max_depth (#2085)
- change: Format session vars (#2088)
- change: Improve error handling for cache deletion (#2092)
- change: Link Livewire single- and multi-file components to their source (#2076)
- change: Remove Star History section from readme
- change: Stringify all model arguments in GateCollector (#2082)
- change: Update CHANGELOG
- change: Update CHANGELOG
- change: Update CHANGELOG
- …and 2 more
Architecture
- Containers 0 added · 0 removed · contexts 1 added · 0 removed · edges 0 added · 0 removed
Added bounded contexts (1)
- fruitcake/laravel-debugbar
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
fruitcake/laravel-debugbar was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 25 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit efbbdc6b2f6e67124eef399d3c3aff2409dd2e1a — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-a9cd699f3cd5.