One major version at a time, following Laravel's official upgrade guide for each step, and upgrading PHP alongside as each version requires. Laravel releases get bug fixes for 18 months and security fixes for 2 years. Laravel 11's security fixes ended on 12 March 2026, so at the time of writing (October 2026) anything older than Laravel 12 gets no security fixes at all.
What's the problem
The app runs on Laravel 8, 9 or 10, maybe on an old PHP version too. Packages won't install, the host wants a newer PHP, and the jump to the current version looks enormous.
Why it happens
- Laravel releases yearly, with a fixed support window. Each version gets two years of security fixes. Skip a few years and you're several versions behind.
- Each version needs specific PHP versions. Upgrading Laravel and upgrading PHP are linked, and old PHP is end of life too.
- Packages follow the framework. Every Composer package has to support the new Laravel version, and abandoned ones won't.
- Breaking changes add up. Each version's changes are small. Four versions' worth at once is not.
How to fix it
- Get it running as it is on its current Laravel and PHP, with a copy of the database, and write down how.
- Add tests for the flows that matter before changing anything, so you can see what each step breaks.
- Check every Composer package for a version that supports the next Laravel version. Plan replacements for abandoned ones.
- Upgrade one major version at a time, following the official upgrade guide for that version. It documents the breaking changes.
- Upgrade PHP when each step requires it. See upgrading PHP safely.
- Run the tests and click through the app after each step, before starting the next.
- Deploy once you're on a supported version, and keep up with yearly releases from then on.
When to call Preventionlabs
If you're one version behind with a handful of packages, the official guides will get you there. Call us when you're several versions behind on both Laravel and PHP, packages have been abandoned, and nobody understands the code well enough to know what each breaking change affects. A resurrection delivers the app running on maintained dependencies, protected to MVP level, deployed in your own hosting account.
Submit your project for a free assessmentFree assessment. $10,000 AUD flat to get it live, only if we take it on and you go ahead.
Sources
- Laravel: Release Notes: Support Policyofficial docs
For all Laravel releases, bug fixes are provided for 18 months and security fixes are provided for 2 years.
- Laravel: Release Notes: support tableofficial docs
11 8.2 - 8.4 March 12th, 2024 September 3rd, 2025 March 12th, 2026
- Laravel: Upgrade Guide (12.x)official docs
We attempt to document every possible breaking change.
- PHP: Supported Versionsofficial docs
Once the four years of support are completed, the branch reaches its end of life and is no longer supported.