🚀 TG4G
Directorypentesthavoc.cloud
📦 pentest 📍 HQ: United States
H

havoc.cloud

Overall Rating
★★★⯨☆ 7.0/10
China Access
★★☆ Basically usable
Quick Check
Data source
ai_pentest · Last updated 2026-06-20

⚡ Score breakdown

5-dim weighted · /10
Performance25% 7.0
Value20% 7.0
China access20% 8.0
Reputation20% 6.0
Support15% 6.5

Dimension scores are derived from public data and fields; weighted into the composite. Reference only.

Editorial Highlights

Framework-aware security scanning for Laravel; Beta available for trial.

In-Depth Review TG4G Review ·2026-06-08 · For reference only

What It Is

HAVOC is a framework-aware security scanning tool for Laravel/PHP, positioned differently from generic SAST tools. It claims to understand Laravel policies, Gates, middleware, and Eloquent scoping, using AST analysis to detect vulnerabilities that are closer to business semantics—such as missing $this->authorize(), mass assignment, Blade XSS, SQL injection, IDOR, privilege escalation, and exposed credentials. It can run locally, via CLI, in GitHub Actions, and as part of PR workflows.

Core Capabilities and Deployment

Its standout capability is “authorization coverage”: it parses public controller methods and checks whether authorize, Gate, can, or route middleware checks are present—similar to code coverage, but for security. In CI, it supports diff-aware scanning, scanning only files changed in a PR while combining results with historical coverage. Output formats include text, json, sarif, and github, making it usable with GitHub Code Scanning. The paid cloud offering provides dashboards, trends, AI triage, auto-fix PRs, team collaboration, and alerts; the Enterprise plan supports a self-hosted scanner so source code does not leave the network. The official site states that source code is cloned and then immediately deleted, with only findings, coverage metrics, and metadata retained.

Pricing and Suitable Scale

The free plan includes 1 repository, CLI/GitHub Action, inline PR comments, status checks, authorization coverage, and all framework analyzers, with unlimited local scanning—making it a strong value. Solo costs $29/month, Team costs $149/month, Business costs $499/month, and Enterprise is custom-priced. Team and above add Slack, Discord, and Email alerts plus exploit test generation; Enterprise includes SAML/SSO, audit logs, a 99.9% SLA, dedicated support, and custom integrations. Billing is handled via Stripe, and paid features come with a 14-day free trial with no credit card required.

Pros and Cons

The main advantage is its deeper understanding of Laravel’s authorization model. It can surface security issues directly as inline PR feedback, generate PHPUnit exploit tests, and create auto-fix PRs, making it well suited for shifting security gates left into the development workflow. The free plan is not just a demo and is friendly to individuals and open-source projects. Its limitation is that deep support currently focuses mainly on Laravel, while Rails and Django are still on the roadmap. The official site also contains two different claims about the number of analyzers—15 and 9—suggesting that documentation consistency could be improved. The product is still in Beta, so detection rate, false positives, and stability should be validated against real repositories.

Access from China and Alternatives

The source material does not provide information on mainland China access, RMB payments, or localized support, so china_access can only be assessed as unknown. Because it depends on GitHub, GitHub OAuth, Stripe, and a cloud dashboard, teams in China should independently verify network connectivity, payment availability, and data compliance. If domestic support or private deployment is required, alternatives to compare include Semgrep, Snyk, SonarQube, GitHub Code Scanning, as well as Chinese code security/DevSecOps vendors—but Laravel framework-semantic analysis capability should be a key point of evaluation.

⚠ This review is compiled from public sources and does not constitute a purchase recommendation. Verify all facts on the vendor's official site. Verify on havoc.cloud official site.

About this entry

havoc.cloud is an United States pentest provider. TG4G tracks its product information, an overall rating of 7.0/10, and a China-accessibility score of Workable. Click "Visit Official Site" to reach havoc.cloud directly.

Get Started

Price not disclosed
Visit havoc.cloud official site →
External link · prices subject to vendor site

Frequently Asked Questions

What is havoc.cloud?
havoc.cloud is a United States-based pentest provider. Framework-aware security scanning for Laravel; Beta available for trial.
Is havoc.cloud good? Is it worth it?
havoc.cloud scores 7.0/10 on TG4G — a solid rating, based in 美国. See the in-depth review below for pros, cons and China accessibility.
Is havoc.cloud usable in China?
havoc.cloud is basically usable in mainland China, though latency may vary by ISP and time of day; have a backup proxy ready. The provider is headquartered in United States and primarily serves overseas markets.
How do I sign up for havoc.cloud?
Visit the havoc.cloud official site to complete sign-up. Registration typically requires an email (Gmail/Outlook recommended) and a payment method. Most overseas services accept credit card / PayPal / crypto. See the "Visit Official Site" button on this page for the direct link.

Browse Other Categories

View the full directory →