Laravel Version Support Schedule Going Into 2027: Which to Run

Laravel Version Support Schedule Going Into 2027: Which to Run

Laravel 11 has had no security fixes since March 12, 2026. Laravel 12 lost its regular bug-fix support on August 13, 2026, and loses security fixes entirely on February 24, 2027, a little over four months from now. If either of those is the version behind a project you run, I want to lay out exactly what that means and what to actually do about it, since Laravel's support model is not quite what a lot of developers assume it is.

The official Laravel support policy

Laravel ships one new major version a year, usually in the first quarter, with minor and patch releases landing most weeks in between. Every major version, since the policy was standardized starting with Laravel 7, gets 18 months of bug fixes followed by a further 6 months of security-only fixes, for 2 years of total support from release. There are no long-term support releases anymore. Laravel 6 was the last version to carry that separate, longer LTS window, and every release since has followed this same standardized schedule regardless of version number. This table reflects the official schedule from Laravel's own release notes.

VersionReleasedBug fixes untilSecurity fixes untilStatus today
Laravel 11Mar 12, 2024Sep 3, 2025Mar 12, 2026End of life
Laravel 12Feb 24, 2025Aug 13, 2026Feb 24, 2027Security fixes only
Laravel 13Mar 17, 2026Q3 2027Mar 17, 2028Active, current major
Laravel 14Q1 2027 (expected)Q3 2028 (estimate)Q1 2029 (estimate)Not yet released

What "security fixes only" actually means in practice

This is the detail I think gets conflated most often, and it is the same pattern we saw when we looked at PHP's own support schedule heading into 2027. Losing bug-fix support does not mean a version is dead. Laravel 12 right now still receives patches for genuinely serious vulnerabilities. What it no longer receives is anything else, small bug fixes, quality of life improvements, compatibility patches for newer PHP point releases. If you hit a non-security bug on Laravel 12 today, the honest answer is that it is very unlikely to ever get fixed in that branch.

If you are still on Laravel 11, this is not a someday problem

Laravel 11 has received zero security patches since March 12, 2026. Any vulnerability discovered in the framework after that date simply has no fix coming for that branch, the exact same exposure we described in detail when PHP 8.1 reached its own end of life. If a client project or your own app is still running Laravel 11, I would treat this as an active, present risk, not a future one.

If you are on Laravel 12, the real deadline is closer than it looks

February 24, 2027 feels far away until you remember a real upgrade, testing included, takes real time to do properly. I would start planning the move to Laravel 13 now rather than treating this as a Q1 2027 fire drill. Laravel 13 requires PHP 8.3 through 8.5, so check your actual PHP version alongside the framework version, since the two upgrades are often tied together in practice.

What I would actually target for a new project today

Laravel 13, released March 17, 2026, is the current major version and the only one carrying full active bug-fix support right now, through roughly Q3 2027. For anything new, this is the obvious choice. Laravel 14 is expected in the first quarter of 2027, but that date is an estimate until it actually ships, and I would not delay a project that needs to start now purely to wait for a version that is not out yet.

If you are weighing infrastructure choices alongside the framework version, this is also worth reading next to our comparison of Laravel Cloud against a plain VPS, since a framework upgrade is a natural moment to reconsider the hosting decision too, not just the Laravel version itself.

The catch: your packages have their own, separate clock

Laravel's own support dates are not the only ones that matter. Most third-party packages only actively maintain compatibility with the latest major Laravel release, dropping support for older versions on their own schedule, often well ahead of Laravel's official dates. A Composer update that refuses to pull in a package's newest version is frequently your first real signal that you are falling behind, not a calendar reminder. I would check your most critical dependencies' own supported-Laravel-version statements before assuming Laravel's table alone tells the whole story.

FAQ

Will my Laravel 11 app stop working now that it is past end of life?
No, it keeps running exactly as before. What stops is any future fix for a newly discovered vulnerability, which means the risk grows the longer it stays untouched, not the app itself breaking on its own.

Is upgrading from Laravel 12 to 13 a big undertaking?
Laravel has generally kept recent major upgrades close to incremental rather than a full rewrite, but actual difficulty depends heavily on your specific packages and any custom code touching internals. I would test on staging and read the official upgrade guide for your specific version jump rather than assume it is trivial.

Does Laravel still offer any long-term support option for a slower upgrade cycle?
No, not since Laravel 6. Every version since follows the same 18-month bug-fix and 2-year total security window, regardless of how large or small that release's changes were.

What PHP version do I need for Laravel 13?
Laravel 13 supports PHP 8.3 through 8.5. If you are still on an older PHP version, that upgrade needs to happen alongside the framework upgrade, not after it.

Should I wait for Laravel 14 instead of upgrading to 13 now?
If you are currently on an unsupported or soon-to-be-unsupported version, I would not wait on an estimated future release date. Move to the current, actively supported version now, and treat the next major as its own upgrade when it actually ships.

Bottom line

Laravel 11 has no security coverage left at all. Laravel 12 loses its remaining security fixes on February 24, 2027, closer than the calendar makes it feel once you account for real upgrade and testing time. Laravel 13 is the version with full active support right now, and it is where I would be planning to land before that date, not after it.

Sources: Laravel official documentation, Release Notes. Verified directly against Laravel's own release notes on October 1, 2026.

Comments 0

Be the first to comment.

Leave a comment