Guide · PHP and LaravelUpdated September 29, 2026

PHP 8.2 end of life: the dates, Laravel and the move to PHP 8.4

PHP 8.2 gets security fixes until December 31, 2026 and nothing after. For a Laravel app the PHP version is only half of it: Laravel 12 is the newest Laravel that still runs on PHP 8.2, and its own security fixes end on February 24, 2027. This guide lists both sets of dates, which versions fit together, and the order we upgrade in.

The dates

From php.net and the Laravel support policy, checked on September 29, 2026.

PHP 8.2
Security fixes until December 31, 2026. Active support already ended on December 31, 2024. PHP: Supported versions
PHP 8.3
Security fixes until December 31, 2027. Active support ended on December 31, 2025. PHP: Supported versions
PHP 8.4
Active support until December 31, 2026, security fixes until December 31, 2028. PHP: Supported versions
PHP 8.5
Released November 20, 2025. Active support until December 31, 2027, security fixes until December 31, 2029. PHP: Supported versions
PHP 8.1
Already end of life since December 31, 2025. The last release was 8.1.34. PHP: Unsupported branches
Laravel 12
Runs on PHP 8.2 to 8.5. Bug fixes ended August 13, 2026; security fixes until February 24, 2027. Laravel 13.x docs: Release notes and support policy
Laravel 13
Released March 17, 2026. Requires PHP 8.3 or newer. Security fixes until March 17, 2028. Laravel 13.x docs: Release notes and support policy

What end of life means

php.net supports each branch in two stages. Under active support, “reported bugs and security issues are fixed and regular point releases are made.” Under security support, a branch gets fixes “for critical security issues only”, with releases “made on an as-needed basis.” After that, “the branch reaches its end of life and is no longer supported.”

PHP 8.2 has been in the security-only stage since the start of 2025. From January 1, 2027 it gets no releases at all, and a vulnerability found in 8.2 after that stays open unless you move.

Which Laravel runs on which PHP

Laravel gives each release 18 months of bug fixes and 2 years of security fixes. The PHP column is the range each version supports.

LaravelPHPReleasedBug fixes untilSecurity fixes until
108.1 – 8.3February 14, 2023August 6, 2024February 4, 2025
118.2 – 8.4March 12, 2024September 3, 2025March 12, 2026
128.2 – 8.5February 24, 2025August 13, 2026February 24, 2027
138.3 – 8.5March 17, 2026Q3 2027March 17, 2028

From the support policy table in the Laravel 13.x release notes. Laravel 10 and 11 are past their security dates; Laravel 12 is security-only.

Who is affected

Any app that runs on PHP 8.2 in production, and any app on 8.1 or older, which is already unsupported. For Laravel apps the question is which pair to land on. On Laravel 10 or 11 the framework itself no longer gets security fixes, whatever PHP it runs on. On Laravel 12 you can move PHP to 8.4 today without touching the framework, but Laravel 12 security fixes end on February 24, 2027, only two months after PHP 8.2.

That is why we target PHP 8.4 with Laravel 13. PHP 8.4 has security support until December 31, 2028, Laravel 13 until March 17, 2028, and Laravel 13 runs on PHP 8.4. It is also why the order matters: Laravel 13 requires PHP 8.3 or newer, so PHP moves first.

What breaks between PHP 8.2 and 8.4

Going from 8.2 to 8.4 crosses two sets of migration notes. These are the items from the PHP manual that most often show up in real code.

  • Implicitly nullable parameters

    function foo(T $a = null) is deprecated in 8.4. Declare it as ?T $a = null. Old packages are full of these, and the deprecation notices flood logs.

  • E_STRICT and trigger_error

    The E_STRICT error level is removed and its constant deprecated; passing E_USER_ERROR to trigger_error() is deprecated. Custom error handlers that reference them need a look.

  • Stricter built-in functions

    In 8.4, round() throws a ValueError for an invalid mode, and exit() and die() with an invalid type throw a TypeError. In 8.3, range() throws on bad input and number_format() handles negative decimals differently.

  • CSV functions

    Relying on the default escape parameter of fputcsv(), fgetcsv() and str_getcsv() is deprecated in 8.4. Pass it explicitly in import and export code.

  • Unbundled extensions

    IMAP, OCI8, PDO_OCI and pspell moved from the PHP core to PECL in 8.4. An app that reads mail over IMAP needs the PECL extension installed on every server.

  • PHP 8.3 changes on the way

    get_class() and get_parent_class() without arguments are deprecated, ++ and -- on non-numeric strings are deprecated in favor of str_increment(), and a negative index on an empty array now continues from that index.

Upgrade steps for a Laravel app

  1. 1. Inventory

    Record the PHP version on every server, CI image and worker, the Laravel version, and each Composer package that sets its own PHP constraint. Mismatches between CI and production are common.

  2. 2. Tests and deprecations on the current PHP

    Get the test suite green and run it with deprecation notices visible. Composer’s config.platform lets you resolve dependencies for the target PHP before the servers change.

  3. 3. PHP 8.4 in CI first

    Run the suite on PHP 8.4 in CI while production stays on 8.2. Fix the failures and the deprecations above, and update packages that do not yet allow PHP 8.4.

  4. 4. PHP 8.4 in production

    Roll out the new PHP image, including queue workers and cron runners, and watch error tracking. Laravel 11 and 12 both run on PHP 8.4, so this step does not need a framework change.

  5. 5. Laravel, one major at a time

    Follow the official upgrade guide for each version. Laravel estimates 5 minutes for 11 to 12 and 10 minutes for 12 to 13; real apps take longer because of packages and custom code, which is what the audit measures.

  6. 6. Laravel 13 specifics

    Update laravel/framework to ^13.0 with PHPUnit 12 or Pest 4. The CSRF middleware is renamed from VerifyCsrfToken to PreventRequestForgery, and Laravel 13 adds symfony/polyfill-php85, which can conflict with legacy helper packages such as laravel/helpers.

PHP 8.4 upgrade checklist

  • PHP version recorded for web servers, workers, cron, CI and local environments.
  • Laravel version and target pair decided: PHP 8.4 with Laravel 13, or PHP 8.4 with Laravel 12 as an interim step.
  • composer.json PHP constraint and config.platform set to the target.
  • Test suite green on PHP 8.4 in CI.
  • Implicitly nullable parameters fixed in your code; packages updated for the rest.
  • IMAP, OCI8 or pspell usage checked and the PECL extensions installed if needed.
  • CSV import and export code passes the escape parameter explicitly.
  • Custom error handlers checked for E_STRICT and E_USER_ERROR.
  • PHP 8.4 in production, including queue workers, before December 31, 2026.
  • Laravel moved to 13 before Laravel 12 security fixes end on February 24, 2027.

Where this comes from

We run Laravel backends in production, and one of them came to us on end-of-life Laravel and PHP versions, with no containers and no CI. We moved it to Docker and GitLab CI and upgraded it to current versions in place, without a rewrite and without taking the site offline. The steps above are the order that worked.

Timeline

  1. 2025-12-31

    PHP 8.1 end of life

    Last release 8.1.34.

  2. 2026-03-17

    Laravel 13 released

    Requires PHP 8.3 or newer.

  3. 2026-08-13

    Laravel 12 bug fixes end

    Laravel 12 continues with security fixes only.

  4. 2026-12-31

    PHP 8.2 end of life

    PHP 8.4 active support also ends; 8.4 continues with security fixes until December 31, 2028.

  5. 2027-02-24

    Laravel 12 security fixes end

    The last Laravel that runs on PHP 8.2 is unsupported.

Questions about PHP 8.2 end of life

When does PHP 8.2 reach end of life?

December 31, 2026, when its security support ends. Active support already ended on December 31, 2024.

Should we go to PHP 8.3, 8.4 or 8.5?

We target 8.4. It has security support until December 31, 2028, every current Laravel (11, 12 and 13) supports it, and packages have had time to catch up. 8.3 ends a year earlier, on December 31, 2027.

Can Laravel 12 run on PHP 8.4?

Yes. Laravel 12 supports PHP 8.2 to 8.5. Its own security fixes end on February 24, 2027, so plan the move to Laravel 13 as well.

Does Laravel 13 run on PHP 8.2?

No. Laravel 13 requires PHP 8.3 or newer, so PHP has to move first.

We are on Laravel 8, 9 or 10. Is this still an upgrade, or a rewrite?

Usually an upgrade, one major version at a time. We have moved a production Laravel site off end-of-life versions in place, without a rewrite. An audit tells you how many steps your app needs and where it will resist.

Next step

30 minutes with an engineer, not a sales rep. You leave knowing what we'd fix first — or that you don't need us.

The first call is free. A code audit of your PHP or Laravel app is a fixed price from $750, credited against the upgrade if you continue within 30 days. A PHP 8.2 to 8.4 upgrade is a fixed price from $1,200.

Sources

  1. PHP: Supported versions
  2. PHP: Unsupported branches
  3. PHP 8.4 release announcement
  4. PHP manual: Backward incompatible changes (PHP 8.3 to 8.4)
  5. PHP manual: Deprecated features in PHP 8.4
  6. PHP manual: Backward incompatible changes (PHP 8.2 to 8.3)
  7. PHP manual: Deprecated features in PHP 8.3
  8. Laravel 13.x docs: Release notes and support policy
  9. Laravel 13.x docs: Upgrade guide
  10. Laravel 12.x docs: Upgrade guide
  11. Composer docs: config.platform

Checked September 29, 2026.