The package had a wire format of its own, and its own notes recorded the cost: Laravel Echo could not talk to it. It now implements the Pusher protocol on ReactPHP — the stack Reverb actually uses, which is what checking rather than assuming turned up. Plus the signature detail that fails in the worst possible way if you get it wrong.
Nova took $resourceKey in its controllers and declared {resource} in its routes, so the container could not resolve the parameter and every one of its routes raised an error instead of rendering. It also claimed /admin, which is how it was finally noticed.
The panel took the resource segment from the URL and used it directly as a table name, so any table in the database could be read, written and deleted through it, and one path interpolated it into raw SQL. Plus a plugin system where a broken plugin cannot take the panel down.
A single encryption key makes rotation an all-or-nothing event, which is why nobody ever rotates. Secure keeps a list, so an old key goes on decrypting what it wrote while new values use the current one. Plus an audit trail and threat detection.
A debug bar has nowhere to render on a JSON response, a redirect or a download. Toolkit reports through Server-Timing instead, which browsers already know how to display, and which cannot alter the response body.
loadMigrationsFrom() was guarded by a check for a binding nothing ever created, so it silently did nothing. Every package following the documented API shipped a migration that could never run. Found by building one.
One command that asks which database you want, installs the skeleton, configures .env, generates the key and makes the first commit. A self-contained executable with no dependencies, because the first thing someone runs is the worst place for an install to fail.
The starter kit shipped no .htaccess, so a deployed application answered the home page and returned 404 for everything else. Three development environments each hid it for a different reason, and the one that shows it is the one you only reach after deploying.
A PHP version that switched in the interface and nowhere else, a FastCGI port that moved when a different site changed version, an updater that asked for draft releases, and a terminal that counted a process dying instantly as success.
What the framework actually looks for: extra.Libxa.providers in composer.json, commands auto-discovered from src/Console/Commands, and the ServiceProvider helpers that work. Written while building two.