Ongoing care

Laravel maintenance and support from developers who read your code

We keep Laravel applications patched, monitored and moving forward. Our developers learn your codebase through a takeover audit, then look after it month after month.

  • Takeover audit to start
  • Updates tested on staging
  • Replies within one business day
What is included
  • Dependency and security updates
  • Queue and scheduler health
  • Error tracking
  • Performance tuning
  • Backups and restore tests
  • Small features and fixes
Get a free quote Reply within one business day. NDA on request.
The problem

How unattended apps quietly decay

A Laravel application does not stay healthy by being left alone. Composer packages publish security fixes. Queue workers die quietly after a server restart. A scheduled job stops running and nobody notices until the monthly invoices fail to go out. A table that held ten thousand rows at launch holds ten million now, and the page that lists it has become the slowest in the system.

Maintenance is how those things get caught while they are small. We look after applications we built and, just as often, applications we did not. Some clients have no developer at all since the original agency moved on. Others have a product team that wants patching, monitoring and minor requests off its plate. In both cases the arrangement is the same: a monthly plan, developers who have read your code and a report showing what was done.

  • Updates have not been run in a year

    Nobody wants to be the one who runs composer update and breaks production. Known vulnerabilities stay unpatched because there is no safe place to test first.

  • Jobs fail and nobody is told

    Queue workers stopped after a deploy, or the scheduler's cron entry vanished in a server move. Emails, exports and syncs silently pile up or never run.

  • Errors are found by customers

    There is no error tracking, only a log file that fills the disk. The first sign of a bug is a support ticket, days after it started.

  • It was fast when it launched

    Pages that were quick with test data now take seconds. Each list screen fires hundreds of queries, and nobody has looked at indexes since the first release.

What we do

What a maintenance plan covers

A plan combines scheduled upkeep with watchful monitoring and a pool of hours for the fixes and small features that always come up.

Dependency and security updates

Composer and npm packages reviewed monthly, security advisories checked on every build, patches applied on staging first and released once the test suite passes.

Queue and scheduler health

Supervised queue workers, Horizon dashboards, alerts on failed jobs and long wait times, and a heartbeat check that proves each scheduled command actually ran.

Error tracking

Exceptions captured with stack trace, user and release in Sentry or Flare, grouped and triaged, with alerts for new or spiking errors.

Performance tuning

N+1 queries removed with eager loading, missing indexes added from slow query logs, expensive results cached and heavy work moved onto queues.

Backups and restore tests

Automated database and file backups stored off the server, with retention rules and a restore that is rehearsed on a schedule instead of assumed.

Small features and fixes

A monthly allowance of development hours for bug fixes, report tweaks, new fields and minor features, tracked per request so you see where time went.

Typical projects

Who we maintain applications for

01

Application with no developer

The agency or freelancer who built it is no longer available. We audit the code, take over hosting access and become the team you call when something needs attention.

02

Support behind a product team

Your developers build features while we handle patching, monitoring, error triage and the backlog of small requests that never reaches the top of a sprint.

03

Post-launch care for a new build

After a project we delivered goes live, the same developers stay on a lighter plan to watch real usage and respond quickly to what it reveals.

04

Performance rescue

A one-off engagement to profile a slow application, fix the worst queries and caching gaps, then continue on a plan to keep it fast.

In depth

What we watch, and why

Takeover starts with an audit

Before we accept responsibility for an application we read it. The audit covers the framework and PHP releases, every Composer dependency and its known advisories, how deployment happens, where secrets are kept, what the scheduler and queues run, whether backups exist and whether anyone has restored one. We also check the basics that get missed: debug mode switched off in production, environment files outside the web root, sensible file permissions and HTTPS enforced. You receive a written report with issues ranked by risk. The first month of a plan usually goes on the top of that list.

Updates as a routine, not an event

Each month we update dependencies on a branch, read the changelogs for anything with a behavior change, run the test suite and deploy to staging. Advisories are checked automatically on every build, so an urgent patch does not wait for the monthly cycle. If the application has few tests, we add them around critical flows as part of the plan, because updates without tests are how maintenance breaks things. Major framework upgrades are larger pieces of work and are handled as described on our Laravel upgrade page.

Queues and the scheduler fail silently

These are the parts of a Laravel application with no user watching them. Workers run under a process supervisor so they restart after a crash, and are restarted on every deploy so they pick up new code. We alert on failed jobs, on queue wait time and on memory use. For the scheduler, each important command reports to a heartbeat monitor when it finishes. If the nightly billing run does not check in, we know that morning, not at month end.

Finding the slow parts

Most Laravel performance problems are database problems. The classic is the N+1 query: a list of fifty orders that loads each customer separately, fifty-one queries where two would do. We find these with query logging and fix them with eager loading, then turn on strict lazy-loading checks in development so new ones are caught before release. Slow query logs point to missing indexes. Results that are expensive and rarely change are cached with an explicit invalidation rule. Only after that do we talk about bigger servers.

What a month looks like

You raise requests through the channel you prefer, and a project manager confirms priority and estimate. Routine work happens on a schedule. At the end of the month you get a short report: updates applied, incidents and their causes, hours used and what we recommend next. If the application runs on something other than Laravel, the same service exists for PHP applications generally.

Process

How support gets started

  1. 1

    Introductory call

    You tell us what the application does, who uses it and what worries you. We explain plan options and what access we need.

  2. 2

    Takeover audit

    We review code, dependencies, hosting, backups and background jobs, and send a ranked report with a recommended plan.

  3. 3

    Onboarding

    Staging, CI, error tracking, uptime and heartbeat monitors are set up, and credentials are moved into a shared vault.

  4. 4

    Monthly cycle

    Updates, monitoring, backups and your requests are handled through the month, with your project manager as the single point of contact.

  5. 5

    Review

    A monthly report and a periodic call cover what changed, what we noticed and what to plan for next.

Deliverables

What you receive each month

  • A written audit of your application and hosting
  • Security patches applied on a schedule
  • Alerts when a job, queue or cron stops
  • Backups with a tested restore procedure
  • A monthly report of work done and hours used
FAQ

Support plan questions

Will you maintain an application you did not build?
Yes, that describes many of the applications we look after. We begin with a takeover audit so we understand the code, hosting and risks before committing to respond to incidents. You do not need the original developers to be involved.
What is included in a monthly plan?
Dependency and security updates, monitoring of errors, uptime, queues and scheduled jobs, backups with restore tests, and a set number of development hours for fixes and small features. The exact mix is agreed after the audit and written into the plan.
How fast do you respond when something breaks?
Monitoring alerts reach us directly, often before users notice. We acknowledge requests within one business day and put production outages ahead of everything else. If you need defined response times or cover outside business hours, we can discuss that when setting up the plan.
What if we need more than small changes?
Larger features are scoped and quoted as separate projects, done by the same developers who maintain the application. Alternatively you can hire a dedicated Laravel developer for ongoing development alongside the plan.
Do you need access to our production server?
Yes, limited to what the work requires: deployment access, logs and the monitoring tools. Hosting accounts stay in your name and credentials are kept in a password vault. We sign an NDA on request before any access is shared.
Can you make our slow Laravel application faster?
Usually, yes. We profile the slowest pages, fix N+1 queries, add indexes, introduce caching and move heavy tasks to queues. Results depend on the cause, so we measure first and report what we found before promising anything.
Are framework version upgrades part of maintenance?
Minor and patch releases are. A major framework upgrade is a bigger task that we plan and quote separately, although being on a plan with tests and CI in place makes it far smaller than it would otherwise be.
Related

From the blog

All articles
Start a project

Want someone watching your Laravel app?

Tell us what it runs on and what has been worrying you. We reply within one business day and can start with a takeover audit.

  • Free consultation and quote
  • NDA on request
  • You own the source code
  • Reply within one business day
Add budget and timeline optional, helps us quote faster

This form is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.