Laravel Requirements in 2026 look stricter on paper than they feel in practice, but a single wrong PHP version, a missing mbstring extension, or a misrouted document root will still take down a fresh install with a blank white screen. This guide spells out the exact PHP version, Composer, extension, server, and database prerequisites you need, plus the deployment traps that trip up even seasoned developers on shared hosting.
Editor's note on Laravel 13: As of early 2026, Laravel has not officially announced a Laravel 13 release date or its final PHP floor. The references to a "March 2026" release and a PHP 8.3 minimum below are based on Laravel's standard release cadence and have been flagged as projections. Treat them as planning assumptions, not confirmed facts, and verify against laravel.com/docs before locking in production timelines.
Overview: What Are Laravel Requirements?
Laravel Requirements are the PHP runtime, Composer, PHP extensions, web server, and database driver your machine or host must expose before a Laravel app will boot. Miss one and you will see a missing autoloader, a fatal Class 'PDO' not found error, or a routing 404 on the first request.
Quick answer to the core query
Laravel needs PHP 8.2 or newer for current release lines, Composer 2.x for dependency management, a small set of C-based PHP extensions, an Apache or Nginx front end, and a supported database. Everything else (Redis, queues, Octane) is optional until your traffic or feature list demands it.
Definition: Laravel Requirements is the umbrella term for the PHP interpreter version, the Composer dependency manager, the C-based PHP extensions Laravel calls into (PDO, mbstring, tokenizer, xml, zip, fileinfo, ctype, json, openssl, bcmath), the web server layer (Apache with mod_rewrite or Nginx with PHP-FPM), and the database driver (MySQL, PostgreSQL, SQLite, or SQL Server) that together allow the framework to load, route, and persist data.
Why they matter in 2026
Laravel ships on a roughly annual release cadence with about 18 months of bug-fix support and a year of security follow-up. Pinning the wrong PHP today creates a forced runtime upgrade on the same day you bump the framework. Plan the runtime and the framework together, or you will pay for it twice.
Common misconceptions debunked
Three myths still circulate in 2026:
- "You need SSH to deploy Laravel." False. You can run
composer installon a local machine and upload thevendor/folder over FTP to a shared host that meets the PHP and extension requirements. - "You need MySQL to start." False. SQLite ships with PHP, costs nothing to enable, and is supported as a first-class driver for prototypes and small production workloads.
- "PHP 7.4 still works." False for anything modern. Laravel 10 was the last line to support PHP 8.1, and Laravel 11+ requires PHP 8.2+.
PHP Version Essentials
Every currently supported Laravel release line in 2026 requires PHP 8.2 or newer. Match the PHP version to the framework version before you write a single line of code.
Minimum PHP 8.1 requirement and the 2026 floor
PHP 8.1 is the minimum Laravel 10 will accept. PHP 8.2 is the working minimum for Laravel 11 and 12. The version-to-version floor for 2026 looks like this:
| Laravel Version | Minimum PHP | Recommended PHP | Support Window |
|---|---|---|---|
| Laravel 10 | 8.1 | 8.2 | Bug fixes ended 2025 |
| Laravel 11 | 8.2 | 8.3 | Bug fixes through 2026 |
| Laravel 12 | 8.2 | 8.3 | Active in 2026 |
| Laravel 13 (projected) | 8.3 (projected) | 8.3 or 8.4 (projected) | Projected: bug fixes through 2027, security through 2028 |
Treat the Laravel 13 row as a working forecast, not a guarantee. Verify the final PHP floor against the official Laravel documentation when the release goes live.
Why 8.1+ is essential for security and features
PHP 8.1 introduced enums, readonly properties, and fibers. PHP 8.3 added typed class constants and the #[\Override] attribute. Laravel's container, queue, and validation layers lean on these features. Running an older interpreter means losing native enums in casts, the Cache::touch() optimization, and array_is_list()-based sorting paths. Security is the bigger motivator: PHP 7.4 has not received a public patch since 2022, and PHP 8.0 is in the same boat.
Legacy PHP support and its limits
You can technically pin a Laravel 9 app to PHP 8.0. You will not, however, be able to install any first-party package released in the last 18 months. The dependency graph pulls in Symfony 7 components, which require PHP 8.2+. Treat the PHP version as a hard gate, not a suggestion.
Composer & Dependency Management
Composer is the dependency manager that pulls in Laravel itself plus every third-party package declared in composer.json. You need Composer 2.x, and you need it working before anything else.
Installing Composer locally
The fastest path to a running app is still the canonical bootstrap command:
composer create-project laravel/laravel my-app
cd my-app
php artisan key:generate
php artisan serve
That single command line scaffolds the framework, generates the .env file, creates an APP_KEY, and starts a local server on port 8000. It mirrors the Simplilearn Laravel reference workflow.
Uploading the vendor folder via FTP
Shared hosts that block shell access still work with Laravel. The trick is to run composer install on a laptop, then upload the entire project tree including the vendor/ directory over FTP. Point the document root at public/, set the .env values in the control panel, and the app boots. The HostingAdvice walkthrough for Hostinger confirms this is the supported path on plans that lack SSH.
Benefits of local Composer over remote installation
Local installs give you reproducible composer.lock files, deterministic dependency resolution, and the ability to mirror production extensions before deploy. On production, always run composer install --optimize-autoloader --no-dev. The flag dumps a class map that turns hundreds of PSR-4 lookups into direct file includes, which matters on hosts where OPcache is disabled or memory is tight.
Web Server & PHP Extensions
Apache with mod_rewrite and Nginx with PHP-FPM are both officially supported. The PHP extension list is small, stable, and easy to audit on most hosts.
Apache vs Nginx configuration
Apache is the default. Point the document root at public/ and Laravel's shipped .htaccess handles the rest. Nginx requires a manual try_files $uri $uri/ /index.php?$query_string; block plus a PHP-FPM upstream. Pick based on your team's operational familiarity, not on the framework's preference.
Required PHP extensions for Laravel
The table below lists every extension Laravel calls into during a normal request lifecycle. Mark the required ones off before you deploy.
| Extension | Purpose | Required |
|---|---|---|
| PDO | Database abstraction | Yes |
| pdo_mysql / pdo_pgsql / pdo_sqlite | Driver for your database | Yes (at least one) |
| mbstring | String handling, UTF-8 | Yes |
| tokenizer | PHP lexing for Eloquent | Yes |
| xml | Config and queue XML parsing | Yes |
| fileinfo | MIME detection on uploads | Yes |
| ctype | Routing and validation | Yes |
| json | Native JSON encode/decode | Yes |
| openssl | Encryption, signed URLs | Yes |
| bcmath | Arbitrary precision math | Yes (Laravel 10+) |
| zip | Package extraction | Yes |
| gd or imagick | Image processing | Optional |
| exif | Photo metadata | Optional |
| opcache | Bytecode cache | Strongly recommended |
How to enable extensions on shared hosts
On cPanel, the Select PHP Version wizard exposes a checkbox grid where you can flip mbstring, intl, and the pdo_mysql driver in one click. Plesk exposes the same controls under PHP Settings → Extensions. If your host hides these toggles, you are locked into whatever they ship. That is a strong signal to upgrade hosting before you upgrade framework.
Database Options
Laravel supports MySQL, PostgreSQL, SQLite, and SQL Server out of the box. The first three cover the vast majority of real-world projects.
MySQL and PostgreSQL for full-featured apps
MySQL 8.0+ and PostgreSQL 14+ are the canonical pair for production Laravel. Both expose JSON columns, full-text search, and the window functions that Eloquent translates into clean query builder calls. Eloquent follows the ActiveRecord pattern, so you can persist objects without writing raw SQL.
SQLite for lightweight or single-file setups
SQLite is a real database, not a toy. Laravel 11 improved its concurrency story, and the file-based format makes it perfect for demos, side projects, and embedded apps. Enable the pdo_sqlite extension, point DB_CONNECTION=sqlite in .env, and create an empty database/database.sqlite file. Migrations run identically to MySQL.
Running Laravel without a database
You can boot a Laravel app that never touches a database. Set DB_CONNECTION=null only if you also disable session and queue drivers that require persistence. Route sessions to the array driver and queues to sync for purely ephemeral workloads. Most real apps still need a database, but the option is there.
Operating System & Hosting Environment
Linux is the path of least resistance. Windows works for local development but adds friction in production.
Linux vs Windows hosting considerations
Path separators, file permissions, and shell utilities all match Laravel's expectations on Linux out of the box. Windows works fine for local development under WSL2 or Laragon. Production on Windows IIS requires URL rewrite rules and careful handling of case-insensitive paths.
Shared hosting, VPS, and cloud provider options
Shared hosting (Hostinger, Bluehost, SiteGround) is cheap and constraining. It works for Laravel if the host supports PHP 8.2+, lets you set environment variables, and exposes a public_html writable directory. VPS (DigitalOcean, Linode, Vultr) gives you root and PHP-FPM control. Managed cloud (AWS, Laravel Vapor, Laravel Forge) abstracts servers entirely and is the right answer once you care about zero-downtime deploys and horizontal scaling.
SSH vs FTP deployment strategies
SSH unlocks composer install on the server, Git pulls, and Artisan-driven deploy hooks. FTP forces the local-then-upload pattern, which is fine for low-traffic sites but breaks down once vendor/ exceeds a few hundred megabytes. Use SSH whenever the host allows it.
Cache & Session Drivers
Laravel's cache layer is pluggable. Pick the driver that matches your host, not the one that looks fastest on paper.
Redis, Memcached, and file-based caching
Redis is the default recommendation because it supports atomic operations, pub/sub, and the Cache::touch() method that extends a key's TTL with a single command. Memcached is faster for pure read-heavy workloads. The file driver works without any external service and is the right choice on shared hosts where you cannot install Redis.
Null and array cache drivers for development
Set CACHE_DRIVER=array in phpunit.xml so tests do not leak state between cases. Use null when you want cache calls to no-op, which is useful in CI pipelines that forbid network access.
Choosing the right driver for performance
For most apps, the right stack is Redis for cache and queue, file driver for local development, and array driver for tests. DynamoDB caching is a niche option for AWS-native shops that want zero infrastructure to manage.
Security & Environment Variables
The .env file holds your database credentials, mail passwords, and the APP_KEY. Treat it like a production secret, not a developer convenience.
Managing .env files securely
Laravel loads .env through the DotEnv library at boot, then exposes values via the env() helper. Never commit .env to Git. Add it to .gitignore on day one and ship a .env.example with placeholder values instead.
DotEnv library and key rotation
Generate a fresh key with php artisan key:generate. Rotating an existing key invalidates every signed URL and encrypted cookie, so do it during a maintenance window and force users to re-authenticate. Store production secrets in the host's secret manager (AWS Secrets Manager, Vault, or the platform's environment variable UI), not in the file system.
HTTPS, CSRF, and other security best practices
Laravel ships with CSRF protection on every state-changing route via the VerifyCsrfToken middleware. Add HTTPS at the load balancer or via a Let's Encrypt certificate, set APP_URL to the secure scheme, and configure cookies with the secure flag. Built-in guards against SQL injection, XSS, and CSRF are why Laravel is considered safer than rolling your own PHP.
Performance & Scalability
You can scale Laravel from a single VPS to a global Kubernetes cluster without rewriting the application. The trick is to match the runtime tuning to the deployment shape.
Laravel Octane for high concurrency
Octane boots the framework once and serves requests from a Swoole or RoadRunner worker pool. It eliminates the per-request bootstrap tax and supports WebSockets natively. The trade-off is that you must be careful with static state and singleton bindings, since the application is no longer stateless between requests.
Optimizing PHP-FPM settings
Tune pm.max_children, pm.start_servers, and pm.max_requests to match available RAM. A common starting point is one worker per 40 MB of memory headroom. Enable OPcache with opcache.validate_timestamps=0 in production so cached bytecode survives across requests without revalidation.
Queue workers and background job handling
Offload anything that takes longer than 200 ms to a queue: email, PDF generation, API webhooks, image processing. The default database queue driver works on shared hosting, but Redis-backed queues are dramatically faster and support delayed jobs, batching, and Horizon's real-time dashboard.
Common Mistakes & Troubleshooting
Most Laravel setup failures cluster around three issues: file permissions, Composer conflicts, and missing extensions. Solve these first before chasing framework bugs.
File permission errors on shared hosting
The storage/ and bootstrap/cache/ directories must be writable by the web server user. On shared hosts this is typically the www-data or apache user. Run chmod -R 775 storage bootstrap/cache and add your FTP user to the same group. A file_put_contents failed to open stream error almost always points here.
Composer dependency conflicts
When composer require fails with a version conflict, run composer why-not vendor/package to see which constraint is blocking the install. The fix is usually a composer update on the blocker or a manual bump of a transitive dependency in composer.json.
Missing PHP extensions and how to fix them
A requires ext-mbstring error during composer install means the extension is missing on the runtime, not in composer.json. Install it with sudo apt install php8.3-mbstring on Debian or Ubuntu, or flip the toggle in the shared host's PHP selector. Verify with php -m | grep mbstring.
Document root misconfiguration
Pointing Apache or Nginx at the project root instead of the public/ directory exposes your .env file to the world. Always set the document root to public/, or use the .htaccess redirect that ships with Laravel when the host forces a public-facing root.
Who Should Use Which Setup?
Mapping the right Laravel deployment to the right reader is the fastest way to avoid months of friction. Use the table below as a starting point, then adjust for your team's skills and budget.
| Target Persona | Recommended Option | Key Reason & Real-World Benefit |
|---|---|---|
| Beginner on a budget | Shared hosting with PHP 8.2+ and FTP | Cheapest path to a live site; install Composer locally and upload vendor/ over FTP |
| Solo developer or freelancer | VPS with Laravel Forge or RunCloud | Git push to deploy, one-click PHP version upgrades, automatic SSL |
| Growing startup | Managed Laravel Vapor on AWS Lambda | Zero server ops, pay-per-request scaling, native queue and database integration |
| Enterprise team | Kubernetes on EKS or GKE with Octane and Redis | Horizontal scaling, multi-region failover, and full control over the runtime |
| Student or hobbyist | Local Laravel Sail, Herd, or Homestead | Free, reproducible, and matches production closely without monthly bills |
Verdict: Beginners should start on shared hosting with FTP-based deploys, then graduate to Forge or Vapor the moment a single client needs more than the host can deliver. The Laravel Requirements evolve with you, not against you.