PluginBench
Skill
Pass
Audit score 90

laravel-best-practices

laravel/boost

Apply Laravel best practices to PHP code: controllers, models, queries, security, validation, and architecture.

What is laravel-best-practices?

A comprehensive guide for writing, reviewing, and refactoring Laravel PHP code. Use this skill when working with controllers, models, migrations, Eloquent queries, jobs, policies, and other Laravel components to ensure consistency, performance, security, and maintainability.

  • Identifies and prevents N+1 query problems and database performance issues
  • Guides authorization, security patterns, input validation, and secret management
  • Reviews controller routing, middleware, form requests, and resource handling
  • Ensures proper job configuration, queue setup, caching strategies, and error handling
  • Validates Eloquent model relationships, scopes, casts, and query optimization
  • Enforces architectural consistency across service classes, actions, and application structure

How to install laravel-best-practices

npx skills add https://github.com/laravel/boost --skill laravel-best-practices
Prerequisites
  • Laravel framework installed in the project
  • Familiarity with Laravel core concepts (controllers, models, routes, middleware)
Claude Code
Cursor
Windsurf
Cline

How to use laravel-best-practices

  1. 1.Check existing patterns in nearby files and the codebase before applying rules
  2. 2.Map your changes to relevant rule files in the index (db-performance, eloquent, security, validation, routing, etc.)
  3. 3.Read the mapped rule files before making edits
  4. 4.Make the smallest coherent change that maintains the application's existing architecture
  5. 5.Verify Laravel version-specific APIs using search-docs or framework inspection
  6. 6.Run tests and formatting checks, then review your diff against all mapped rules

Use cases

Good for
  • Writing new Laravel controllers, models, or service classes with correct patterns
  • Refactoring existing Laravel code to follow framework best practices and eliminate performance issues
  • Reviewing Laravel pull requests to catch security, N+1, and architectural inconsistencies
  • Optimizing Eloquent queries and database access patterns in large applications
  • Setting up jobs, scheduled commands, caching, and queue configuration correctly
Who it's for
  • Laravel backend developers
  • PHP developers building or maintaining Laravel applications
  • Code reviewers ensuring Laravel project consistency
  • Developers optimizing Laravel application performance

laravel-best-practices FAQ

Should I follow these rules if my codebase uses a different pattern?

No. Check what the application already does first. Consistency is more important than following a theoretically better pattern. Only deviate for correctness or security defects.

Which rule file should I read for N+1 query problems?

Read `rules/db-performance.md` for query count, eager loading, indexes, and large dataset handling. For complex queries, also see `rules/advanced-queries.md`.

What should I do for authentication and input validation?

Read `rules/security.md` for authentication, authorization, input safety, and secrets. Read `rules/validation.md` specifically for Form Requests and validation rules.

How do I know which rules apply to my change?

Map your affected concerns to the rule index. For example, if modifying a model relationship, read `rules/eloquent.md`. If adding a job, read `rules/queue-jobs.md`. Cross-cutting changes often need multiple rule files.

Should I introduce a new pattern if it's better than the existing one?

No, unless the existing pattern has a correctness or security defect. Keep the application's architecture and naming consistent instead of introducing a second way to solve the same problem.

Full instructions (SKILL.md)

Source of truth, from laravel/boost.


name: laravel-best-practices description: "Apply this skill whenever writing, reviewing, or refactoring Laravel PHP code. This includes creating or modifying controllers, models, migrations, form requests, policies, jobs, scheduled commands, service classes, and Eloquent queries. Triggers for N+1 and query performance issues, caching strategies, authorization and security patterns, validation, error handling, queue and job configuration, route definitions, and architectural decisions. Also use for Laravel code reviews and refactoring existing Laravel code to follow best practices. Covers any task involving Laravel backend PHP code patterns." license: MIT metadata: author: laravel

Laravel Best Practices

Best practices for Laravel, organized as an index of rule files. Each rule file teaches what to do and why. For exact API syntax, verify with search-docs.

Consistency First

Before applying any rule, check what the application already does. Laravel offers multiple valid approaches, and the best choice is the one the codebase already uses, even if another pattern would be theoretically better. Inconsistency is worse than a suboptimal pattern.

Check sibling files, related controllers, models, or tests for established patterns. If one exists, follow it. Don't introduce a second way. These rules are defaults for when no pattern exists yet, not overrides.

How to Apply

  1. Check the changed files, nearby code, project configuration, and relevant tests for established patterns. Deviate only for a correctness or security defect, and call the deviation out.
  2. Map every affected concern to the rule index below. Read each mapped rule file before editing. Skip unrelated rule files.
  3. Make the smallest coherent change. Keep the application's architecture and naming instead of introducing a second pattern for the same job.
  4. Verify version-sensitive Laravel APIs for the installed version with search-docs, or inspect the installed framework when it is unavailable.
  5. Run the narrowest relevant tests first, then the project's formatting and static-analysis checks when the change warrants them.
  6. Re-read the diff against every mapped rule before finishing.

Rule Index

Cross-cutting changes often need more than one rule file.

ConcernRead
Query count, eager loading, indexes, large datasetsrules/db-performance.md
Subqueries, aggregates, complex ordering and query plansrules/advanced-queries.md
Models, relationships, scopes, castsrules/eloquent.md
Authentication, authorization, input safety, secrets, uploadsrules/security.md
Form Requests and validation rulesrules/validation.md
Controllers, route binding, resources, middlewarerules/routing.md
Schema changes, columns, foreign keys, indexesrules/migrations.md
Jobs, retries, uniqueness, batches, Horizonrules/queue-jobs.md
Cache lifetime, invalidation, locks, memoizationrules/caching.md
Outbound requests, retries, timeouts, fakesrules/http-client.md
Exceptions, reporting, rendering, log contextrules/error-handling.md
Events and notificationsrules/events-notifications.md
Mailables and mail assertionsrules/mail.md
Scheduled tasks and overlap protectionrules/scheduling.md
Collections, lazy iteration, bulk operationsrules/collections.md
Blade components, attributes, composersrules/blade-views.md
Environment values and application configurationrules/config.md
Tests: coverage, factories, fakes, and assertionsthe testing-best-practices skill
Naming, helpers, file boundaries, PHP stylerules/style.md
Actions, services, dependencies, application structurerules/architecture.md

Decision Rules

  • Prefer framework features and existing application abstractions over new helpers or dependencies.
  • Avoid speculative abstractions. Extract code when it creates a clear domain boundary, removes meaningful duplication, or makes behavior independently testable.
  • Keep database access out of Blade views and prevent hidden N+1 queries across controllers, resources, jobs, and serialization.