All posts

The indexes you're missing (and the one that's hurting you)

Published July 11, 2026 · by Majd Ghithan, written with the help of AI

The indexes you're missing (and the one that's hurting you)

A client sent me a query that took 4.2 seconds. One WHERE, one ORDER BY, a table with three million rows. I added a single index and it dropped to 11 milliseconds. They asked if I'd rewritten the query. I hadn't touched it. I just told the database how to find the rows instead of making it read all of them.

Indexing is the highest-leverage thing you can do to a slow Laravel app, and most of what's written about it stops at "add an index to columns you search." That's true but it's the beginner half. Here's the rest.

Composite indexes: order is everything

You filter orders by status and then sort by created_at. Two separate single-column indexes won't help much — the database can usually only use one of them for a query like this. What you want is one composite index across both:

Schema::table('orders', function (Blueprint $table) {
    $table->index(['status', 'created_at']);
});

The catch nobody mentions: the column order inside the index matters, and it has to match how you query. A composite index on (status, created_at) works like a phone book sorted by last name, then first name. It's brilliant for "find everyone named Ghithan, sorted by first name." It's useless for "find everyone whose first name is Majd" — wrong leading column.

So the rule is: the columns you filter on with = go first, and the column you sort or range-scan on goes last. WHERE status = ? ORDER BY created_at wants (status, created_at), in exactly that order.

Same query, 3M rows, one index added
4,2001,90011No indexTwo single-col indexesComposite (status, created_at)
ms

The middle bar is the trap. People add an index per column, see it get "a bit faster," and assume they're done. The composite is two orders of magnitude better because it satisfies the filter and the sort from one structure.

Index your foreign keys

Laravel creates a foreign key constraint when you write foreignId('user_id')->constrained(). What a lot of people don't realise is that in MySQL an FK constraint usually gets an index automatically — but the moment you define the FK manually, or you're on a setup where it doesn't, every Order::where('user_id', $id) and every with('orders') eager-load becomes a full table scan.

Any column you join on or filter a relationship by needs an index. If you have a comments table with post_id and you ever load $post->comments, post_id must be indexed. This is the single most common missing index I find, because the relationship "just works" in development — it's only slow, never broken.

Covering indexes: skip the table entirely

Here's the trick that feels like cheating. If an index contains every column a query needs — both the ones it filters on and the ones it returns — the database can answer the query from the index alone and never touch the table. That's a covering index.

// Query: select id, status from orders where user_id = ?
$table->index(['user_id', 'status', 'id']);

Now SELECT id, status FROM orders WHERE user_id = ? reads only the index. No jumping back to the table row for each match. On a hot endpoint that returns a small set of columns, this is often the difference between "fast" and "instant." You don't need it everywhere — reach for it on your top three slowest read queries.

When an index hurts

This is the part the tutorials skip, and it's why "just index everything" is wrong advice.

Every index is a copy of some columns that the database has to keep sorted. That copy isn't free — it's maintained on every INSERT, UPDATE, and DELETE. On a write-heavy table, each extra index is a tax on every write.

Read-heavy table — index freely
orders, products, users
read 1000s of times per write
index every filter + sort column
covering indexes on hot reads
Write-heavy table — index sparingly
events, logs, telemetry, audit_trail
written constantly, read rarely
every index slows every insert
keep only what a real query needs

I once watched an events table's insert throughput drop by a third because someone had added six indexes "to be safe." Five of them were never used by any query. We dropped them, writes recovered, and nothing got slower — because nothing was reading those columns anyway.

Read EXPLAIN before you guess

Stop guessing which index you need. Ask the database:

EXPLAIN SELECT id, status FROM orders WHERE user_id = 42 ORDER BY created_at;

Two things to look at. type: if it says ALL, that's a full table scan — the thing you're trying to kill. You want ref or range. And rows: the estimated number of rows examined. If it's reading two million to return twenty, you're missing an index. After you add one, run EXPLAIN again and watch rows collapse and type change from ALL to ref.

Indexing isn't a dark art. It's telling the database the shape of the questions you're going to ask, so it can prepare an answer instead of searching from scratch every time. Read your slow query log, EXPLAIN the top offenders, and add the specific index each one is begging for. Then stop — the goal is the indexes your queries actually use, not the most indexes you can fit.

🤖 Heads up: this post was drafted with AI. Spot something wrong or off?Edit it on GitHub & open a PR
Majd Ghithan

Majd Ghithan

Full-Stack Engineer & Tech Lead

More posts

Laravel finally resizes images for you

Laravel finally resizes images for you

Every Laravel app I've built that takes an avatar ended the same way: composer require intervention/image, wire up a facade, write a little service class, and hope the next dev…

July 26, 2026Read more
What actually breaks at 100,000 users (that never breaks in a demo)

What actually breaks at 100,000 users (that never breaks in a demo)

The first time I shipped a dashboard to a hundred thousand active users, nothing I had tested was what broke. Everything that failed had passed every check I ran. It worked on m…

July 25, 2026Read more
Where your queue jobs go to die under load

Where your queue jobs go to die under load

The support ticket said "I never got my invoice email." I checked the logs. The job ran. It succeeded. failedjobs was empty. Everything said the email went out. It did not.

July 18, 2026Read more
Caching in Laravel without the stampede

Caching in Laravel without the stampede

We cached the homepage's "trending products" query for five minutes. It was our slowest query — about 900ms, a big aggregation across orders. Caching it took the homepage from s…

July 4, 2026Read more
Taking one endpoint from 800ms to 80ms

Taking one endpoint from 800ms to 80ms

The order-details endpoint took 800 milliseconds. Not broken, just slow enough that the app felt heavy everywhere it was used. The team's instinct was "the server needs more mem…

June 27, 2026Read more
The N+1 you can't see (it's hiding in your accessors)

The N+1 you can't see (it's hiding in your accessors)

I've fixed hundreds of N+1 queries. The easy ones are right there in the controller — a foreach with $order-customer inside it, obvious the moment you read the code. Those aren'…

June 20, 2026Read more
The Friday deploy that charged customers twice

The Friday deploy that charged customers twice

It was 4:40 on a Friday. The change was tiny — a one-line tweak to how we called the payment provider, plus a bump to the queue worker's timeout. Small, tested, reviewed. I depl…

June 13, 2026Read more
Code review people don't dread

Code review people don't dread

I once left forty-one comments on a junior's pull request. I was proud of it. Thorough, I told myself. The next day he barely made eye contact, and his next PR sat open for a we…

June 6, 2026Read more
Hiring a mid-level Laravel dev: the signals that actually matter

Hiring a mid-level Laravel dev: the signals that actually matter

The best hire I ever made failed my first question. I asked him to explain service containers and he stumbled, went quiet, then said "honestly I use them every day but I've neve…

May 30, 2026Read more
Saying no to a feature without being the 'no' person

Saying no to a feature without being the 'no' person

For about a year I was the engineer everyone learned to route around. Not because I was wrong, I was usually right, but because my answer to new ideas was a flat "no, that'll br…

May 23, 2026Read more
My first 90 days as a tech lead (and the habit I had to break)

My first 90 days as a tech lead (and the habit I had to break)

Three weeks into leading my first team, I stayed late to "help" by rewriting a junior's feature myself. It was faster my way. I pushed it, felt productive, went home. The next m…

May 16, 2026Read more
Breaking down the task that scares you

Breaking down the task that scares you

There's a specific kind of ticket that makes my stomach drop. Not the hard ones, hard is fine. It's the ambiguous ones. "Migrate billing to the new provider." "Add multi-tenancy…

May 9, 2026Read more
1:1s that aren't just status updates

1:1s that aren't just status updates

For my first few months as a lead, my 1:1s were thirty minutes of me asking "so, what are you working on?" and nodding at answers I already knew from standup. We both left sligh…

May 2, 2026Read more
Get the business logic out of your controllers

Get the business logic out of your controllers

I once opened a OrderController@store method that was 240 lines long. Validation, a discount calculation, three model writes, a Stripe charge, two emails, a Slack notification,…

April 25, 2026Read more
Form Requests are the most underrated thing in Laravel

Form Requests are the most underrated thing in Laravel

Most Laravel devs meet Form Requests once, in a tutorial, use them to hold a rules() array, and never look deeper. That's a shame, because a Form Request is the cleanest place i…

April 18, 2026Read more
Testing Laravel without mocking everything

Testing Laravel without mocking everything

I inherited a codebase once with 900 unit tests and no confidence. Every test mocked the repository, mocked the model, mocked the mailer, mocked the thing three layers down. The…

April 11, 2026Read more
Three Eloquent features that clean up your models

Three Eloquent features that clean up your models

The messiest Laravel model I ever wrote wasn't messy because of Eloquent. It was messy because I ignored the parts of Eloquent that exist specifically to keep it clean. The same…

April 4, 2026Read more
The migration that locked the table for eight minutes

The migration that locked the table for eight minutes

The deploy looked boring. One migration, adding a lastseenat column to the users table with a default of now(). I'd written a hundred like it. I ran it at 2pm on a Tuesday becau…

March 28, 2026Read more
Chasing a memory leak in a Laravel queue worker

Chasing a memory leak in a Laravel queue worker

The alert came in at 4am: one of our queue:work processes had been OOM-killed. The supervisor restarted it, it processed jobs for about forty minutes, and got killed again. It w…

March 21, 2026Read more