Now liveThe Skillselion MCP - thousands of ranked skills, loaded into your agent mid-task. No install.Get it →
laravel avatar

Laravel Best Practices

  • 788 installs
  • 3.6k repo stars
  • Updated August 4, 2026
  • laravel/boost

laravel-best-practices is an agent skill that applies prioritized Laravel conventions for routing, Eloquent, validation, services, testing, and structure for developers who need maintainable production PHP applications.

About

laravel-best-practices is an agent guidance skill from laravel/boost that teaches Laravel conventions prioritized by impact, covering routing, Eloquent, validation, services, testing, and project structure for production PHP apps. Its consistency-first rule tells agents to match existing codebase patterns before introducing new ones, treating inconsistency as worse than a theoretically better alternative. Rules are organized by topic such as database performance in rules/db-performance.md, and agents verify exact API syntax with the search-docs tool rather than guessing framework APIs. Developers reach for laravel-best-practices when scaffolding new Laravel features, reviewing PHP pull requests, or refactoring controllers and models toward framework idioms. The skill is guidance for day-to-day Laravel coding rather than environment setup or deployment automation. It assumes an existing Laravel project where established sibling files can be checked for patterns before changes land.

  • Eloquent patterns
  • Validation habits
  • Service structure
  • Routing conventions
  • Testing practices

Laravel Best Practices by the numbers

  • 788 all-time installs (skills.sh)
  • +59 installs in the week ending Aug 2, 2026 (Skillselion tracking)
  • Ranked #14 of 65 PHP & Laravel skills by installs in the Skillselion catalog
  • Data as of Aug 5, 2026 (Skillselion catalog sync)
npx skills add https://github.com/laravel/boost --skill laravel-best-practices

Add your badge

Show developers this skill is listed on Skillselion. Paste this into your README.

Listed on Skillselion
Installs788
repo stars3.6k
Last updatedAugust 4, 2026
Repositorylaravel/boost

What Laravel conventions should production PHP apps follow?

Apply Laravel conventions for routing, Eloquent, validation, services, testing, and project structure in maintainable production PHP applications.

Who is it for?

Developers building or refactoring Laravel backends who want agent-enforced framework idioms matched to existing project patterns.

Skip if: Teams not using Laravel or developers who only need generic PHP advice without framework-specific routing, Eloquent, or validation rules.

When should I use this skill?

The user writes Laravel PHP code involving routing, Eloquent, validation, services, testing, or asks for Laravel best practices.

What you get

Convention-aligned Laravel routes, models, validation rules, service classes, tests, and documented pattern choices.

  • Convention-aligned Laravel code
  • Validated routing and service structure

By the numbers

  • Includes dedicated database performance rules in rules/db-performance.md
  • Organizes guidance into prioritized topic rule files within laravel/boost

Files

SKILL.mdMarkdownGitHub ↗

Laravel Best Practices

Best practices for Laravel, prioritized by impact. Each rule teaches what to do and why. For exact API syntax, verify with search-docs.

Consistency First

Before applying any rule, check what the application already does. Laravel offers multiple valid approaches — the best choice is the one the codebase already uses, even if another pattern would be theoretically better. Inconsistency is worse than a suboptimal pattern.

Check sibling files, related controllers, models, or tests for established patterns. If one exists, follow it — don't introduce a second way. These rules are defaults for when no pattern exists yet, not overrides.

Quick Reference

1. Database Performance → rules/db-performance.md

  • Eager load with with() to prevent N+1 queries
  • Enable Model::preventLazyLoading() in development
  • Select only needed columns, avoid SELECT *
  • chunk() / chunkById() for large datasets
  • Index columns used in WHERE, ORDER BY, JOIN
  • withCount() instead of loading relations to count
  • cursor() for memory-efficient read-only iteration
  • Never query in Blade templates

2. Advanced Query Patterns → rules/advanced-queries.md

  • addSelect() subqueries over eager-loading entire has-many for a single value
  • Dynamic relationships via subquery FK + belongsTo
  • Conditional aggregates (CASE WHEN in selectRaw) over multiple count queries
  • setRelation() to prevent circular N+1 queries
  • whereIn + pluck() over whereHas for better index usage
  • Two simple queries can beat one complex query
  • Compound indexes matching orderBy column order
  • Correlated subqueries in orderBy for has-many sorting (avoid joins)

3. Security → rules/security.md

  • Define $fillable or $guarded on every model, authorize every action via policies or gates
  • No raw SQL with user input — use Eloquent or query builder
  • {{ }} for output escaping, @csrf on all POST/PUT/DELETE forms, throttle on auth and API routes
  • Validate MIME type, extension, and size for file uploads
  • Never commit .env, use config() for secrets, encrypted cast for sensitive DB fields

4. Caching → rules/caching.md

  • Cache::remember() over manual get/put
  • Cache::flexible() for stale-while-revalidate on high-traffic data
  • Cache::memo() to avoid redundant cache hits within a request
  • Cache tags to invalidate related groups
  • Cache::add() for atomic conditional writes
  • once() to memoize per-request or per-object lifetime
  • Cache::lock() / lockForUpdate() for race conditions
  • Failover cache stores in production

5. Eloquent Patterns → rules/eloquent.md

  • Correct relationship types with return type hints
  • Local scopes for reusable query constraints
  • Global scopes sparingly — document their existence
  • Attribute casts in the casts() method
  • Cast date columns, use Carbon instances in templates
  • whereBelongsTo($model) for cleaner queries
  • Never hardcode table names — use (new Model)->getTable() or Eloquent queries

6. Validation & Forms → rules/validation.md

  • Form Request classes, not inline validation
  • Array notation ['required', 'email'] for new code; follow existing convention
  • $request->validated() only — never $request->all()
  • Rule::when() for conditional validation
  • after() instead of withValidator()

7. Configuration → rules/config.md

  • env() only inside config files
  • App::environment() or app()->isProduction()
  • Config, lang files, and constants over hardcoded text

8. Testing Patterns → rules/testing.md

  • LazilyRefreshDatabase over RefreshDatabase for speed
  • assertModelExists() over raw assertDatabaseHas()
  • Factory states and sequences over manual overrides
  • Use fakes (Event::fake(), Exceptions::fake(), etc.) — but always after factory setup, not before
  • recycle() to share relationship instances across factories

9. Queue & Job Patterns → rules/queue-jobs.md

  • retry_after must exceed job timeout; use exponential backoff [1, 5, 10]
  • ShouldBeUnique to prevent duplicates; ShouldBeUniqueUntilProcessing for early lock release
  • Always implement failed(); with retryUntil(), set $tries = 0
  • RateLimited middleware for external API calls; Bus::batch() for related jobs
  • Horizon for complex multi-queue scenarios

10. Routing & Controllers → rules/routing.md

  • Implicit route model binding
  • Scoped bindings for nested resources
  • Route::resource() or apiResource()
  • Methods under 10 lines — extract to actions/services
  • Type-hint Form Requests for auto-validation

11. HTTP Client → rules/http-client.md

  • Explicit timeout and connectTimeout on every request
  • retry() with exponential backoff for external APIs
  • Check response status or use throw()
  • Http::pool() for concurrent independent requests
  • Http::fake() and preventStrayRequests() in tests

12. Events, Notifications & Mail → rules/events-notifications.md, rules/mail.md

  • Event discovery over manual registration; event:cache in production
  • ShouldDispatchAfterCommit / afterCommit() inside transactions
  • Queue notifications and mailables with ShouldQueue
  • On-demand notifications for non-user recipients
  • HasLocalePreference on notifiable models
  • assertQueued() not assertSent() for queued mailables
  • Markdown mailables for transactional emails

13. Error Handling → rules/error-handling.md

  • report()/render() on exception classes or in bootstrap/app.php — follow existing pattern
  • ShouldntReport for exceptions that should never log
  • Throttle high-volume exceptions to protect log sinks
  • dontReportDuplicates() for multi-catch scenarios
  • Force JSON rendering for API routes
  • Structured context via context() on exception classes

14. Task Scheduling → rules/scheduling.md

  • withoutOverlapping() on variable-duration tasks
  • onOneServer() on multi-server deployments
  • runInBackground() for concurrent long tasks
  • environments() to restrict to appropriate environments
  • takeUntilTimeout() for time-bounded processing
  • Schedule groups for shared configuration

15. Architecture → rules/architecture.md

  • Single-purpose Action classes; dependency injection over app() helper
  • Prefer official Laravel packages and follow conventions, don't override defaults
  • Default to ORDER BY id DESC or created_at DESC; mb_* for UTF-8 safety
  • defer() for post-response work; Context for request-scoped data; Concurrency::run() for parallel execution

16. Migrations → rules/migrations.md

  • Generate migrations with php artisan make:migration
  • constrained() for foreign keys
  • Never modify migrations that have run in production
  • Add indexes in the migration, not as an afterthought
  • Mirror column defaults in model $attributes
  • Reversible down() by default; forward-fix migrations for intentionally irreversible changes
  • One concern per migration — never mix DDL and DML

17. Collections → rules/collections.md

  • Higher-order messages for simple collection operations
  • cursor() vs. lazy() — choose based on relationship needs
  • lazyById() when updating records while iterating
  • toQuery() for bulk operations on collections

18. Blade & Views → rules/blade-views.md

  • $attributes->merge() in component templates
  • Blade components over @include; @pushOnce for per-component scripts
  • View Composers for shared view data
  • @aware for deeply nested component props

19. Conventions & Style → rules/style.md

  • Follow Laravel naming conventions for all entities
  • Prefer Laravel helpers (Str, Arr, Number, Uri, Str::of(), $request->string()) over raw PHP functions
  • No JS/CSS in Blade, no HTML in PHP classes
  • Code should be readable; comments only for config files

How to Apply

Always use a sub-agent to read rule files and explore this skill's content.

1. Identify the file type and select relevant sections (e.g., migration → §16, controller → §1, §3, §5, §6, §10) 2. Check sibling files for existing patterns — follow those first per Consistency First 3. Verify API syntax with search-docs for the installed Laravel version

Related skills

How it compares

Use laravel-best-practices for opinionated Laravel convention guidance during coding; use framework docs lookup when you only need raw API reference without project-pattern enforcement.

FAQ

Does laravel-best-practices override existing project patterns?

laravel-best-practices prioritizes consistency first. Agents should match sibling controllers, models, and tests already in the codebase before introducing a second valid Laravel pattern, even when another approach looks theoretically better.

How does laravel-best-practices handle uncertain Laravel API syntax?

laravel-best-practices tells agents to verify exact Laravel API syntax with search-docs rather than guessing. Topic rules such as rules/db-performance.md provide prioritized guidance while docs lookup confirms current framework APIs.

This week in AI coding

Five minutes, every Monday - the tools, releases and tactics for developers.

unsubscribe anytime.