Skip to content
Back to skills

Laravel

ASecurity

Build PHP web applications with Laravel: routing, Eloquent ORM, Blade, migrations, validation, and deployment. Use for PHP backends.

  • 2 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added October 1, 2026
ai-agentsgophpbashapibackendsecurityperformance

Works with

  • api

Security analysis

A100/100

Pro scans all 2 files and shows the line behind each finding

Scanned October 1, 2026

npx -y skills add ssrjkk/agent-skills --skill laravel --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Laravel?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Laravel
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/ssrjkk-laravel/badge)](https://www.skillsdirectory.com/skills/ssrjkk-laravel)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: laravel
description: "Build PHP web applications with Laravel: routing, Eloquent ORM, Blade, migrations, validation, and deployment. Use for PHP backends."
category: backend
tags: [laravel, php, eloquent, blade, migrations, artisan, backend]
models: [sonnet, opus, gpt-6, gemini-3, glm-5]
version: 1.0.0
created: 2026-09-29
updated: 2026-09-29
author: ssrjkk
---
# Laravel

> Building robust PHP web applications with Laravel.

## Quick Start
```bash
composer create-project laravel/laravel my-app
cd my-app && php artisan serve
# http://localhost:8000
```

## When to Use
- PHP monoliths with clean MVC structure
- CRUD apps needing rapid development
- Teams wanting batteries-included tooling
- Projects with Blade templates or JSON APIs

## Best Practices

### Structure
- Follow the app structure: controllers, models, services
- Keep controllers thin; business logic in services/actions
- Use route-model binding for resourceful routes
- Organize by feature when it grows

### Eloquent & Migrations
- Define migrations for every schema change
- Use Eloquent relationships and eager loading
- Add indexes; avoid N+1 queries
- Use form requests for validation

### Validation & Errors
- Validate with Form Requests
- Return consistent JSON error shapes for APIs
- Handle exceptions centrally
- Use proper HTTP status codes

### Security & Performance
- Use Blade escaping to prevent XSS
- Mass assignment: whitelist fillable fields
- Cache hot queries and views
- Queue heavy jobs

## Dependencies
```bash
composer create-project laravel/laravel my-app
php artisan serve
```

## Examples
```php
// routes/web.php
Route::get('/users/{user}', [UserController::class, 'show']);

// app/Http/Controllers/UserController.php
class UserController extends Controller
{
    public function show(User $user)
    {
        return view('users.show', ['user' => $user]);
    }
}
```
```php
// Migration
Schema::create('users', function (Blueprint $table) {
    $table->id();
    $table->string('email')->unique();
    $table->timestamp('created_at')->nullable();
});
```
```php
// Model with relationship and fillable
class User extends Authenticatable
{
    protected $fillable = ['name', 'email'];
    protected $hidden = ['password'];

    public function posts()
    {
        return $this->hasMany(Post::class);
    }
}
```
```php
// Form request validation
class StoreUserRequest extends FormRequest
{
    public function rules()
    {
        return [
            'name' => 'required|string|max:255',
            'email' => 'required|email|unique:users',
        ];
    }
}
```

## Step-by-Step
1. Scaffold with `composer create-project`.
2. Configure DB and set up the environment.
3. Create migrations and Eloquent models.
4. Build routes and controllers.
5. Add Form Requests for validation.
6. Write Blade templates or JSON API responses.
7. Add auth, caching, and queues.
8. Test with Pest/PHPUnit and deploy.

## Validation
1. `php artisan test` passes
2. Migrations apply cleanly
3. Validation rejects bad input
4. No obvious N+1 in key routes
5. App runs in production mode

## Troubleshooting
- N+1: use `with()` eager loading.
- Mass assignment: set `$fillable` correctly.
- Slow responses: cache queries and views, queue jobs.

Files in this skill

  • SKILL.md3.2 KB
  • SKILL.ru.md4.1 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…