One major version costs $1,500 and a full move from Laravel 8 to 13 costs $3,500, after a free audit. Here's where the hours go, which packages hold an upgrade up, and why the tests get written first.
The app works. Orders come in, staff log in, and nobody has opened composer.json in three years. Then the host announces it's retiring PHP 8.1, or a payment library won't install, and someone asks what an upgrade will cost. Our answer is $1,500 for one major Laravel version and $3,500 for a full move from Laravel 8 or later up to Laravel 13, both fixed prices agreed after a free written audit. Apps on Laravel 7 or older start at $6,000, because most of them get rebuilt side by side. Here's where that money goes, and why two apps on the same version can cost different amounts.
Which Laravel versions still get security fixes
Laravel ships one major release a year, around the first quarter. Under the support policy in the Laravel release notes, each release gets bug fixes for 18 months and security fixes for two years. As of October 2026 the table reads like this:
| Version | Released | Security fixes until | PHP it runs on | Where it stands |
|---|---|---|---|---|
| Laravel 10 | 14 Feb 2023 | 4 Feb 2025 | 8.1 to 8.3 | No fixes of any kind |
| Laravel 11 | 12 Mar 2024 | 12 Mar 2026 | 8.2 to 8.4 | No fixes of any kind |
| Laravel 12 | 24 Feb 2025 | 24 Feb 2027 | 8.2 to 8.5 | Security only, bug fixes ended 13 Aug 2026 |
| Laravel 13 | 17 Mar 2026 | 17 Mar 2028 | 8.3 to 8.5 | Current |
Laravel 9 and everything before it has dropped off the table entirely. So anything below 12 is running without security patches today, and 12 has under five months left.
PHP is often the real deadline
The framework is one clock. PHP is the other, and it's the one your host enforces. PHP 8.1 reached end of life on 31 December 2025. PHP's own support table gives 8.2 security releases until 31 December 2026 and 8.3 until 31 December 2027.
Read the two tables together and the trap shows up. Laravel 10 can't run on anything newer than PHP 8.3. When a host moves its servers to 8.4, an app on Laravel 10 is running on a PHP version its framework was never supported on, with no fix coming if something breaks. That's the point where an upgrade turns from a budget line into an emergency, and emergencies cost more than planned work.

Why the official 70 minutes turns into days
Every Laravel upgrade guide opens with an estimate. From 8 to 13 they read 30 minutes, 10, 15, 5 and 10. That adds up to 70 minutes.
Those numbers are fair for an app that is close to the stock skeleton. They don't describe a business app with a checkout, a PDF generator, an error tracker and a mail provider, each pulled in as a third-party package. The guides themselves say so. The Laravel 9 upgrade guide tells you to examine any other third-party packages and confirm each supports the new version, and that one sentence is where most of the hours go.
What the audit looks at
Before anyone quotes, someone has to read the app. A useful audit answers five questions in writing:
- Which Laravel and PHP versions are in composer.lock, and which PHP the server really runs.
- Which packages have a release for each version on the path, which need replacing, and which are abandoned.
- Where the code touches areas that changed: mail, file storage, dates, queues, CSRF handling.
- Whether there are tests, and whether they pass on the current version.
- Whether the host can move PHP, or the app needs to move host.
Our fixed-price Laravel upgrade starts with that audit, free. If it shows the app won't fit a fixed price, you're told so with a range before you pay anything.
Packages that hold an upgrade up
The framework's own changes are documented and mostly mechanical. The surprises live in the packages around it. These are the ones that come up on the path from 8 to 13:
Mail, in Laravel 9. Laravel 9 replaced SwiftMailer, unmaintained since December 2021, with Symfony Mailer. Anything that customised messages through the old Swift methods has to be rewritten, and the old Postmark driver package has to come out.
File storage, in Laravel 9. Flysystem moved from version 1 to 3. Failed writes now return false instead of throwing, and writes overwrite existing files by default. Upload code that relied on an exception to spot a failure goes quiet, which is worse than breaking loudly.
Logging, in Laravel 10. Monolog 3 arrived, and error trackers such as BugSnag or Rollbar may need newer versions of their Laravel packages to follow.
First-party packages, in Laravel 11. Cashier Stripe 14, Passport 11, Sanctum 3 and Telescope 4 aren't supported on Laravel 11. Each needs its next major version, and their migrations now have to be published into the app.
Dates, in Laravel 12. Laravel 12 requires Carbon 3, where the diffIn methods return floats and can come back negative. Billing code that counts the days between two dates is exactly where this bites.
An abandoned package is the expensive case. If a PDF library or an old admin panel never got a release for the next version, it has to be replaced, and the code that used it rewritten around the replacement.
Why tests come before any code changes
An upgrade with no tests can only prove the home page loads. So the first job is smoke tests on the parts that make or lose money: logins, checkout and billing, and the admin. They run after every version step, and the client keeps them afterwards.
Tests won't make every decision for you. Laravel 13 ships a new default that stores sessions as JSON, and switching an existing app over logs every user out. In Laravel 11, a migration that changes a column drops any attribute it doesn't restate, such as a default or unsigned. Those are judgement calls to make before go-live, not on launch day.
We also move one major version per commit. Jumping straight to the latest release hides which step broke what. Small commits are easy to review and easy to roll back.

What a Laravel upgrade costs
| You're on | The path | Package | Price |
|---|---|---|---|
| Laravel 12 | 12 to 13 | One version up | $1,500 fixed |
| Laravel 8 to 11 | Every version up to 13 | Full upgrade | $3,500 fixed |
| Laravel 5 to 7 | Rebuilt side by side on 13, in most cases | Legacy upgrade | From $6,000, quoted after the audit |
| Laravel 13 | Nothing to upgrade | Care plan | From $490 a month |
Both fixed prices include the audit, packages updated or replaced, logins, payments and admin tested on staging, the production deploy and a 30-day fix warranty. The full upgrade adds one commit per major version and moving PHP to a supported version with your host. New features aren't in the price, and neither are front-end rewrites such as Vue 2 to Vue 3. Those get quoted separately, which keeps the upgrade itself a fixed number.
Laravel 7 and older: upgrade or rebuild?
Apps this old tend to sit on PHP 7, and PHP 7.4 reached end of life on 28 November 2022. Walking one through six major versions in place means rewriting most of it anyway, one compatibility fix at a time. Building it again on Laravel 13 beside the old app, then switching over, is the shorter road. That's why legacy work starts at $6,000 and is priced after the audit.
If the rebuild turns into a wish list of new features, it stops being an upgrade. At that point it's worth reading what building a SaaS product from scratch costs before deciding.
A worked example
An illustrative case, so the path is visible: a booking app on Laravel 9 with PHP 8.1, Sanctum 2 for its mobile API, an older Rollbar package for error tracking and an invoice job that counts overdue days with Carbon. The path is 9 to 10 to 11 to 12 to 13, four commits. Along the way the Rollbar package moves to a release that supports Monolog 3, Sanctum moves to version 4 with its migrations published, the overdue-days code is checked against Carbon 3, and PHP goes to 8.3 or newer. Nothing in that list is unusual, so it sits inside the $3,500 full upgrade. Add a PDF library with no release past Laravel 9, and the audit flags it before any price is agreed.
Staying current afterwards
A new major version lands every year. Paying $1,500 each spring is one option. The other is a care plan: Essentials at $490 a month with 5 hours of changes, Business at $890 with 10, or Priority at $1,590 with 20 hours and the yearly Laravel upgrade included. Plans run for three months minimum, then monthly.
How to check which version you're on
Run php artisan --version on the server, or search composer.lock for the line that names laravel/framework. Check the PHP version in your hosting panel too. Those two numbers place you in the first table above, and they're the first thing any quote will need.
Questions people ask before an upgrade
Can I skip versions and go straight from Laravel 9 to 13?
Composer will let you change the version number in one go, but every breaking change from the 10, 11, 12 and 13 guides applies. Doing it one version at a time doesn't add work. It makes each change small enough to test and roll back.
Is it safe to stay on Laravel 12 for now?
Until 24 February 2027. Bug fixes already ended on 13 August 2026, so from here on only security patches arrive. Plan the move to 13 before February.
Will our users be logged out by the upgrade?
Only if you choose to. Laravel 13's skeleton stores sessions as JSON, and switching an existing app to that setting signs everyone out. Keeping the old setting keeps sessions alive.
Do we have to move to the new folder structure from Laravel 11?
No. The Laravel 11 upgrade guide recommends against it, because Laravel 11 was built to run the older structure as it is.
What about automated upgrade tools?
The official guides point to Shift, a community-maintained service that automates the mechanical changes. It saves typing. It doesn't decide what replaces an abandoned package or check that checkout still works afterwards.
What does the free audit need from us?
The site's address, and the Laravel and PHP versions if you know them.