{{ $x }} prints through htmlspecialchars; {!! $x !!} prints raw, which is safe only for HTML you produced. Here an attacker wrote the review and the shop's editors wrote the blurb:
{{-- A Blade comment never reaches the browser --}}
<p>{{ $review->author }} wrote: {{ $review->body }}</p>
<p>{!! $blurbHtml !!}</p>
<p>{{ 'Tom & Jerry' }}</p>
<p>Vue sees: @{{ cartCount }}</p><p>Mallory wrote: <script>steal(document.cookie)</script></p>
<p>A <em>classic</em> on software craft.</p>
<p>Tom &amp; Jerry</p>
<p>Vue sees: {{ cartCount }}</p>The script is defused. Blade double-encodes existing entities unless you call Blade::withoutDoubleEncoding(). @{{ }} (or a @verbatim block) leaves braces for Vue 5,482 or Alpine, and {{ Js::from($data) }} writes JSON that is safe inside <script> (Contextual Escaping).
Where compiled views live. Each template compiles to PHP in storage/framework/views, named by an xxh128 hash of its path, and recompiles when the template is newer than that file:
<p><?php echo e($review->author); ?> wrote: <?php echo e($review->body); ?></p>
<p><?php echo $blurbHtml; ?></p>
<p><?php echo e('Tom & Jerry'); ?></p>
<p>Vue sees: {{ cartCount }}</p>
<?php /**PATH /var/www/bookshop/resources/views/reviews/show.blade.php ENDPATH**/ ?>{{ }} became e(), {!! !!} a bare echo, and the comment a blank line; the PATH trailer lets error pages name the template. Deployments run php artisan view:cache (Production Deployment), which here reported "Blade templates cached successfully" and wrote 76 files; view:clear empties the folder.