This Securing Laravel tip is the blunt warning I fully agree with: don’t use phpinfo() in your app. The scary part is the XSS-to-admin-exfiltration scenario—middleware isn’t a real safety net when the output includes environment variables and potentially your APP_KEY.
You'll be taken to Securinglaravel to complete your purchase.