Laravel Version Support Schedule Going Into 2027: Which to Run
Laravel 11 has had no security fixes since March 12, 2026. Laravel 12 lost its regular bug-fix support on August 13, 2026, and loses security fixes entirely on February 24, 2027, a little over four months from now. If either of those is the version behind a project you run, I want to lay out exactly what that means and what to actually do about it, since Laravel's support model is not quite what a lot of developers assume it is.
The official Laravel support policy
Laravel ships one new major version a year, usually in the first quarter, with minor and patch releases landing most weeks in between. Every major version, since the policy was standardized starting with Laravel 7, gets 18 months of bug fixes followed by a further 6 months of security-only fixes, for 2 years of total support from release. There are no long-term support releases anymore. Laravel 6 was the last version to carry that separate, longer LTS window, and every release since has followed this same standardized schedule regardless of version number. This table reflects the official schedule from Laravel's own release notes.
| Version | Released | Bug fixes until | Security fixes until | Status today |
|---|---|---|---|---|
| Laravel 11 | Mar 12, 2024 | Sep 3, 2025 | Mar 12, 2026 | End of life |
| Laravel 12 | Feb 24, 2025 | Aug 13, 2026 | Feb 24, 2027 | Security fixes only |
| Laravel 13 | Mar 17, 2026 | Q3 2027 | Mar 17, 2028 | Active, current major |
| Laravel 14 | Q1 2027 (expected) | Q3 2028 (estimate) | Q1 2029 (estimate) | Not yet released |
What "security fixes only" actually means in practice
This is the detail I think gets conflated most often, and it is the same pattern we saw when we looked at PHP's own support schedule heading into 2027. Losing bug-fix support does not mean a version is dead. Laravel 12 right now still receives patches for genuinely serious vulnerabilities. What it no longer receives is anything else, small bug fixes, quality of life improvements, compatibility patches for newer PHP point releases. If you hit a non-security bug on Laravel 12 today, the honest answer is that it is very unlikely to ever get fixed in that branch.
If you are still on Laravel 11, this is not a someday problem
Laravel 11 has received zero security patches since March 12, 2026. Any vulnerability discovered in the framework after that date simply has no fix coming for that branch, the exact same exposure we described in detail when PHP 8.1 reached its own end of life. If a client project or your own app is still running Laravel 11, I would treat this as an active, present risk, not a future one.
If you are on Laravel 12, the real deadline is closer than it looks
February 24, 2027 feels far away until you remember a real upgrade, testing included, takes real time to do properly. I would start planning the move to Laravel 13 now rather than treating this as a Q1 2027 fire drill. Laravel 13 requires PHP 8.3 through 8.5, so check your actual PHP version alongside the framework version, since the two upgrades are often tied together in practice.
What I would actually target for a new project today
Laravel 13, released March 17, 2026, is the current major version and the only one carrying full active bug-fix support right now, through roughly Q3 2027. For anything new, this is the obvious choice. Laravel 14 is expected in the first quarter of 2027, but that date is an estimate until it actually ships, and I would not delay a project that needs to start now purely to wait for a version that is not out yet.
If you are weighing infrastructure choices alongside the framework version, this is also worth reading next to our comparison of Laravel Cloud against a plain VPS, since a framework upgrade is a natural moment to reconsider the hosting decision too, not just the Laravel version itself.
The catch: your packages have their own, separate clock
Laravel's own support dates are not the only ones that matter. Most third-party packages only actively maintain compatibility with the latest major Laravel release, dropping support for older versions on their own schedule, often well ahead of Laravel's official dates. A Composer update that refuses to pull in a package's newest version is frequently your first real signal that you are falling behind, not a calendar reminder. I would check your most critical dependencies' own supported-Laravel-version statements before assuming Laravel's table alone tells the whole story.
FAQ
Will my Laravel 11 app stop working now that it is past end of life?
No, it keeps running exactly as before. What stops is any future fix for a newly discovered vulnerability, which means the risk grows the longer it stays untouched, not the app itself breaking on its own.
Is upgrading from Laravel 12 to 13 a big undertaking?
Laravel has generally kept recent major upgrades close to incremental rather than a full rewrite, but actual difficulty depends heavily on your specific packages and any custom code touching internals. I would test on staging and read the official upgrade guide for your specific version jump rather than assume it is trivial.
Does Laravel still offer any long-term support option for a slower upgrade cycle?
No, not since Laravel 6. Every version since follows the same 18-month bug-fix and 2-year total security window, regardless of how large or small that release's changes were.
What PHP version do I need for Laravel 13?
Laravel 13 supports PHP 8.3 through 8.5. If you are still on an older PHP version, that upgrade needs to happen alongside the framework upgrade, not after it.
Should I wait for Laravel 14 instead of upgrading to 13 now?
If you are currently on an unsupported or soon-to-be-unsupported version, I would not wait on an estimated future release date. Move to the current, actively supported version now, and treat the next major as its own upgrade when it actually ships.
Bottom line
Laravel 11 has no security coverage left at all. Laravel 12 loses its remaining security fixes on February 24, 2027, closer than the calendar makes it feel once you account for real upgrade and testing time. Laravel 13 is the version with full active support right now, and it is where I would be planning to land before that date, not after it.
Sources: Laravel official documentation, Release Notes. Verified directly against Laravel's own release notes on October 1, 2026.
Comments 0
Be the first to comment.
Leave a comment