TL;DR: Junior Laravel interviews test whether you can build a small CRUD feature end to end: a route, a controller, a validated form, a migration, an Eloquent model and a Blade view. Know the current version too: Laravel 13 needs PHP 8.3 or newer, and a fresh app starts on SQLite.
A new Laravel 13 app creates its own SQLite database file and runs its first migrations before you open an editor, so a junior's first task is rarely "set up the database". It is adding a feature that follows the framework's conventions.
The questions below are the ones interviewers use to check that you know where code goes and what Laravel does for you. For senior topics such as queues, the service container and Octane, see our advanced Laravel interview questions.
- 1Each Laravel release gets 18 months of bug fixes and 2 years of security fixes, with one major release a year.
- 2A new app has no
routes/api.phpuntil you runphp artisan install:api, which also installs Sanctum. - 3The official starter kits now come in four flavours: React, Svelte, Vue and Livewire, all using Fortify for login.
- 4
composer run devstarts the web server, queue worker and Vite together in one command.
Laravel Basics
1. What is Laravel, and what does MVC mean in it?
Laravel is a free, open-source PHP framework for building web applications and APIs.
It follows the Model-View-Controller pattern: models talk to the database, views produce the HTML, and controllers take a request, use models, and return a view or a response.
Laravel adds a lot around that core: routing, validation, authentication, queues, mail, testing tools and a command-line tool called Artisan. The point is that common tasks already have a standard place and a standard way.
2. How do you create a new Laravel project?
With the Laravel installer: laravel new example-app. The installer asks which starter kit you want, if any, and which database to use. Then you install the frontend packages and start everything:
laravel new example-app
cd example-app
npm install && npm run build
composer run dev
The app is then at http://localhost:8000. On macOS and Windows, Laravel Herd installs PHP, Composer and the installer in one step and serves every project in ~/Herd on a .test domain.
3. What is Composer, and what are composer.json and the vendor folder?
Composer is PHP's package manager. composer.json lists the packages your project needs, composer.lock records the exact versions installed, and vendor/ holds the downloaded code.
You commit composer.json and composer.lock to Git, never vendor/. Anyone who clones the project runs composer install to get the same versions. Laravel itself is a Composer package, laravel/framework.
4. Which folders in a Laravel project should you know first?
app/: your PHP code: models inapp/Models, controllers inapp/Http/Controllers.routes/:web.phpfor browser routes,console.phpfor scheduled tasks and commands.resources/views/: Blade templates.database/: migrations, factories and seeders.config/: settings files;public/: the web root withindex.php;storage/: logs, cache and uploaded files.

An interviewer often asks "where would you put this?" for a piece of code. A clear answer shows you have built something, not only read the docs.
5. What is the .env file, and why is it not committed?
The .env file holds settings that change between machines: the database password, APP_KEY, mail credentials, APP_DEBUG.
Committing it would leak secrets to anyone with access to the repository, so it stays out of Git and .env.example is committed instead as a template.
In code, read settings with config('app.name'), not env(). The config files read .env once, and after php artisan config:cache in production, env() calls outside the config files return null.
6. What is Artisan, and which commands do you use every day?
Artisan is Laravel's command-line tool, run as php artisan. The everyday ones:
make:model Post -mfc: a model with its migration, factory and controller in one go.migrate,migrate:rollback,migrate:fresh --seed.route:list: every route, its name, controller and middleware.tinker: a live PHP shell with your app loaded, handy for trying queries.test: runs the test suite.
Routing and Controllers
7. How do you define a route, and what is the difference between web and API routes?
A route maps an HTTP method and a URL to code. Browser routes go in routes/web.php:
use App\Http\Controllers\PostController;
Route::get('/posts', [PostController::class, 'index']);
Route::post('/posts', [PostController::class, 'store']);
Web routes get sessions, cookies and CSRF protection. A new Laravel app has no API routes file. Running php artisan install:api creates routes/api.php and installs Sanctum for token authentication.
Routes in that file are stateless and get an /api prefix automatically.
8. How do route parameters work?
Put the parameter in braces and it is passed to your controller method. A ? makes it optional, and constraints limit what it matches:
Route::get('/posts/{id}', [PostController::class, 'show'])->whereNumber('id');
Route::get('/tags/{name?}', [TagController::class, 'index']);
Without the constraint, /posts/abc would reach the controller and fail there. With it, Laravel returns a 404 straight away.
9. What are named routes, and why use them?
A named route has a name you use instead of its URL: Route::get('/posts/{post}', ...)->name('posts.show'), then route('posts.show', $post) in code and Blade.
If the URL later changes from /posts to /articles, every link keeps working because they point at the name, not the path.
10. What does Route::resource create?
One line registers seven routes for a CRUD controller, each mapped to a method with a fixed name:
| Method | URL | Action |
|---|---|---|
| GET | /posts | index |
| GET | /posts/create | create |
| POST | /posts | store |
| GET | /posts/{post} | show |
| GET | /posts/{post}/edit | edit |
| PUT/PATCH | /posts/{post} | update |
| DELETE | /posts/{post} | destroy |
php artisan make:controller PostController --resource creates the controller with all seven methods empty. Route::apiResource skips create and edit, which only exist to show HTML forms.
11. What is route model binding?
When a route parameter's name matches a type-hinted model in the controller, Laravel loads that model for you:
Route::get('/posts/{post}', [PostController::class, 'show']);
public function show(Post $post)
{
return view('posts.show', ['post' => $post]);
}
If no post has that ID, Laravel returns a 404 automatically. It saves writing Post::findOrFail($id) at the top of every method.
12. What is middleware? Give an example.
Middleware is code that runs before (and optionally after) a request reaches your controller.
The auth middleware sends guests to the login page; guest does the opposite for pages like "Register"; verified blocks users who have not confirmed their email.
Route::middleware('auth')->group(function () {
Route::get('/dashboard', DashboardController::class);
});
You create your own with php artisan make:middleware, for example to block users whose account is suspended.
Blade and Forms
13. What is Blade, and what is the difference between {{ }} and {!! !!}?
Blade is Laravel's template language.
Files end in .blade.php and compile to plain PHP. {{ $name }} prints a value with HTML escaped, so a user who types <script> into their name cannot run it on your page. {!! $html !!} prints raw HTML without escaping.
Use {!! !!} only for HTML you generated and trust yourself, never for anything a user typed. Loops and conditions use directives such as @if, @foreach and @forelse.
14. How do layouts and components work in Blade?
Components let you write a piece of HTML once and reuse it. A file at resources/views/components/alert.blade.php is used as <x-alert type="error">Message</x-alert>, and whatever you put between the tags arrives as $slot.
A page layout is usually a component too: <x-layout> wraps each page with the shared header and footer. The older @extends and @section style still works and appears in many existing projects.
15. What does @csrf do, and why do forms need it?
@csrf adds a hidden field with a token tied to the user's session.
Laravel's CSRF protection rejects POST, PUT, PATCH and DELETE requests from the browser without a valid token, which stops another site from submitting a form on your users' behalf.
<form method="POST" action="{{ route('posts.update', $post) }}">
@csrf
@method('PUT')
<input name="title" value="{{ old('title', $post->title) }}">
</form>
HTML forms only send GET and POST, so @method('PUT') adds a hidden field that tells Laravel to treat the request as a PUT.
16. How do you validate form input?
Call $request->validate() with rules. If anything fails, Laravel redirects back to the form with the errors and the old input; your code below never runs.
public function store(Request $request)
{
$data = $request->validate([
'title' => ['required', 'string', 'max:255'],
'body' => ['required'],
]);
Post::create($data);
return redirect()->route('posts.index')->with('status', 'Post created.');
}
In the view, @error('title') shows the message for one field and old('title') refills it. For bigger forms, move the rules into a form request class made with php artisan make:request StorePostRequest.

Database and Eloquent
17. What are migrations, and why use them?
A migration is a PHP file that changes the database schema: creating a table, adding a column, adding an index. Migrations live in version control, so every developer and every server builds the same schema by running php artisan migrate.
Schema::create('posts', function (Blueprint $table) {
$table->id();
$table->foreignId('user_id')->constrained();
$table->string('title');
$table->text('body');
$table->timestamps();
});
Once a migration has run on a shared database, do not edit it. Write a new migration for the next change.
18. What are factories and seeders?
A factory describes how to make fake records for a model, and a seeder uses factories or plain inserts to fill the database. Together they give every developer realistic test data with one command:
// database/seeders/DatabaseSeeder.php
User::factory()->count(10)->create();
// terminal
php artisan migrate:fresh --seed
Tests use the same factories, so test data and development data come from one place.
19. What conventions does an Eloquent model follow?
A model named Post maps to a table named posts, uses id as its primary key, and manages created_at and updated_at automatically. You only override these when your table breaks the pattern, for example with protected $table = 'blog_posts';.
Following the conventions is what lets php artisan make:model, route model binding and relationships work with no extra configuration.
20. How do you create, read, update and delete records with Eloquent?
$post = Post::create(['title' => 'Hello', 'body' => '...']); // create
$post = Post::findOrFail($id); // read, or 404
$post->update(['title' => 'New title']); // update
$post->delete(); // delete
$recent = Post::where('published', true)->latest()->get(); // query
create() and update() with an array only accept fields listed in the model's $fillable property. That rule stops a user from setting a field such as is_admin by adding it to the form.
21. How do you define basic relationships?
A method on the model returns the relationship. A user has many posts and a post belongs to a user:
class User extends Model
{
public function posts(): HasMany
{
return $this->hasMany(Post::class);
}
}
class Post extends Model
{
public function user(): BelongsTo
{
return $this->belongsTo(User::class);
}
}
Then $user->posts is a collection and $post->user is one model. Many-to-many, such as posts and tags, uses belongsToMany and a pivot table named post_tag.
22. When would you use the query builder instead of Eloquent?
Eloquent returns model objects with relationships, casts and events, which suits most application code. The query builder, DB::table('posts'), returns plain rows and skips the model layer.
The query builder fits reports, bulk updates and queries that join several tables where you only need a few columns.
Both build SQL with bound parameters, so both are safe from SQL injection as long as you do not paste user input into raw SQL strings.
Everyday Features
23. How do you handle file uploads?
Validate the file, then store it on a disk:
$request->validate(['avatar' => ['required', 'image', 'max:2048']]);
$path = $request->file('avatar')->store('avatars', 'public');
The public disk saves files under storage/app/public. Running php artisan storage:link once makes them reachable at /storage/.... The form needs enctype="multipart/form-data", which is the most common reason an upload arrives empty.
24. How do you add login and registration to a new app?
Pick a starter kit when you run laravel new.
The official starter kits come in React, Svelte, Vue and Livewire versions, and all of them use Laravel Fortify for login, registration, password reset, email verification and two-factor authentication.
The kit's code is copied into your app, so you can change any screen. There is also a WorkOS AuthKit variant for social login, passkeys and SSO.
25. How do you debug a problem in Laravel?
dd($value)dumps a value and stops;dump()dumps and carries on.- Errors and
Log::info()messages go tostorage/logs/laravel.log. php artisan tinkerlets you run the query or method in isolation.- With
APP_DEBUG=truelocally, errors show a full stack trace in the browser.
APP_DEBUG=true on a live server shows stack traces, and sometimes environment values, to anyone who triggers an error. Production runs with APP_DEBUG=false.26. How do you write a basic test?
Feature tests send a request to your app and check the response. Run them with php artisan test:
public function test_guests_are_redirected_from_the_dashboard(): void
{
$this->get('/dashboard')->assertRedirect('/login');
}
public function test_users_can_see_their_posts(): void
{
$user = User::factory()->create();
$this->actingAs($user)->get('/posts')->assertOk();
}
Laravel supports both PHPUnit and Pest. A junior who can write these two tests for their own feature already stands out.
What Changed Recently
27. Which Laravel version should a new project use, and how long is it supported?
Laravel 13, released on March 17, 2026. It needs PHP 8.3 to 8.5. Per the release notes, every release gets bug fixes for 18 months and security fixes for 2 years, so Laravel 13 has security fixes until March 17, 2028.
Laravel 12 stopped getting bug fixes on August 13, 2026 and gets security fixes until February 24, 2027. Laravel 11 is past end of life.
28. What does a fresh Laravel app give you before you write any code?
Since Laravel 11, the skeleton is smaller: fewer config files, no routes/api.php until you ask for it, and application settings such as middleware registered in bootstrap/app.php.
Per the installation guide, the default .env points at SQLite, and the installer creates database/database.sqlite and runs the first migrations.
So a new developer can clone, install and run the app with no database server at all. Switching to MySQL or PostgreSQL means changing the DB_* values in .env and running php artisan migrate.
29. What changed in the starter kits?
Laravel 12 introduced new starter kits, and per its release notes, Breeze and Jetstream no longer receive updates. Today there are four kits, each built on Tailwind and Inertia or Livewire:
- React 19 with shadcn/ui
- Vue 3 with shadcn-vue
- Svelte 5 with shadcn-svelte
- Livewire 4 with Flux UI
- Reactive pages written in Blade and PHP
- No separate JavaScript framework to learn
A junior should be able to say which one they used and why. For a team that mostly writes Blade, Livewire is the natural fit.
30. What are controller attributes in Laravel 13?
Laravel 13 lets you declare middleware and authorization directly on a controller with PHP attributes, instead of in the route file:
use Illuminate\Routing\Attributes\Controllers\Authorize;
use Illuminate\Routing\Attributes\Controllers\Middleware;
#[Middleware('auth')]
class CommentController
{
#[Authorize('create', [Comment::class, 'post'])]
public function store(Post $post)
{
// ...
}
}
The route stays a plain Route::post(...), and anyone reading the controller sees its rules in one place. Route-file middleware still works, so older projects do not need to change.
Signs of a Strong Answer
- They answer "where does this go?" with a specific file and folder, not "in Laravel".
- They add
@csrf, validation and$fillablewithout being reminded. - They use named routes and
route()instead of hard-coded URLs. - They know
{{ }}escapes output and can say when{!! !!}is unsafe. - They have written at least one feature test for their own code.
- They know which Laravel and PHP version their last project ran on.
Hiring Laravel Developers
Junior Laravel developers learn fastest next to seniors who review their code. Second Talent matches companies with pre-vetted PHP and Laravel developers at every level, screened with questions like these.
Tell us the stack and we send a shortlist within 24 hours. Start hiring, or practise with our PHP coding challenges.






