Adds Laravel 13 compatibility and IPv6 CIDR matching while retaining Laravel 11/12 support.
Fixes bundled maintenance view loading/publishing, literal route pattern matching, named/API route detection before global middleware dispatch, and malformed CIDR handling. Enable/disable commands now atomically update the active environment file with its existing permissions, fail without success events when persistence fails, and clear stale configuration/status caches.
Compatibility and operations
- Laravel 11/12 require PHP 8.2+; Laravel 13 requires PHP 8.3+. Tested through PHP 8.5.
- After enabling/disabling, rebuild configuration caches if your deployment uses them and restart long-running workers or Octane processes.
--clear-cacheremains accepted for existing scripts. IfAPP_READ_ONLYcomes from external environment variables, update it through your deployment. - Laravel 11 is outside security support. Use patched Laravel 12 or 13 in production. Laravel 11 CI compatibility tests allow only its four known unpatched framework advisory IDs (
PKSA-d5tc-s1qs-h781,PKSA-m5cs-t1y6-qpcs,PKSA-3r5d-mb8f-1qw9,PKSA-mdq4-51ck-6kdq). These exceptions do not change application security policy.
The complete suite passes across 11 PHP/Laravel combinations: 86 tests and 184 assertions. Current Laravel 12/13 dependency audits are clean. Laravel 11 with PHP 8.5 emits two upstream Testbench runtime deprecations.