Expensive? How?
Thanks to Let's encrypt and others, certificates are now free.
Let's Encrypt is still far from being convenient and usable for small companies or individuals that don't want to manage infrastructures and administration like writing a cron job that refreshes your certificate.
The lack of raised hands, should answer for you why LetsEncrypt is not ready for mainstream use.
Until Cert renewal is baked into all the hosting apps/platforms - HTTPs will never be ubiquitous.
Not that they host it with their own computers, but they rent some space online and host it there.
EDIT: Replied to the wrong parent, please ignore in this context.
EDIT: You can't delete comments with replies anymore. It's very annoying.
I also host with WPEngine, a more progressive WordPress only host - which has made SSL implementation extremely simple. They're an example of a modern approach to web hosting.
It's the low cost, shared (LAMP) hosting providers that need to implement it into their sales process and make switching existing non-encrypted sites smooth. Unfortunately, I don't see them moving to "free SSL for everyone!" anytime soon as it's a revenue generator for most.
(it's not exclusive to just laravel apps)