NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Packagist · #4437 most downloaded on Packagist
Blasp is a powerful and customisable profanity filter package for Laravel applications
Last release 6 months ago
27 Mar 2026
Release timing varies
gaps range from 2 weeks to 6 months
Most releases are documented
notes for 12 of 20 stable releases
Nothing withdrawn
no release was ever pulled
2 years old
20 releases · first in 2024
One column per month.
Invisible Unicode bypass : Strip \p{Cf} format characters (zero-width spaces, invisible separators) from input before processing, so profanity like f
\p{Cf} format characters (zero-width spaces, invisible separators) from input before processing, so profanity like fuck (with U+2063) is correctly detected* as a universal letter substitution so censored profanity like f*g, s**t, f**k is detected\x01 instead of * for internal masking during detection loop to prevent re-matching masked textpreg_replace returning null on malformed UTF-8 inputA ground-up rewrite with a driver-based architecture, severity scoring, and deep Laravel integration.
A ground-up rewrite with a driver-based architecture, severity scoring, and deep Laravel integration.
regex (obfuscation/substitution detection), pattern (fast exact matching), phonetic (sound-alike evasion via metaphone + Levenshtein), and pipeline (chain multiple drivers together). Extend with custom drivers.*, #), grawlix (!@#$%), or a custom callback.Blaspable trait auto-sanitizes or rejects profanity on model save, with withoutBlaspChecking() for bypassing.CheckProfanity middleware to reject or sanitize profane request fields with configurable severity and field filtering.blasp_check rule with language support.@clean($text) for output sanitization.Str::isProfane(), Str::cleanProfanity(), and Stringable equivalents.ProfanityDetected, ContentBlocked, ModelProfanityDetected.Blasp::fake() for test doubles with assertions.Blaspsoft\Blasp\Laravel\ merged into Blaspsoft\Blasp\. Update any direct class references.ServiceProvider → BlaspServiceProvider (auto-discovery handles this).config/config.php → config/blasp.php. Re-publish with php artisan vendor:publish --tag="blasp-config".check() now returns a Result object with isOffensive(), clean(), score(), severity(), count(), words(), uniqueWords(). Previous methods like hasProfanity(), getCleanString(), getProfanitiesCount() are removed.Fix false positives when profanity is a substring of a regular word — Words like space , spacious , aerospace , workspace were incorrectly flagged bec
space, spacious, aerospace, workspace were incorrectly flagged because the profanity spac matched as a substring. Instead of adding more words to the false positives list, a systematic check now automatically skips pure alphabetic profanity matches embedded inside larger regular words.spac, fuck, ass)sp@c, f-u-c-k, a$$)fucks, fucker, fuckings)cuntfuck, fuckingshitcuntfuck)ccuunntt, fuuuck)space, spacious, aerospace, cocktails, class, etc.)Closes #32
Fixed false positives when profanity detection incorrectly matched across separate words:
"an alert" no longer flags "anal""has 5 faces" no longer flags "ass"The fix distinguishes between intentional obfuscation (like "@ss" which contains letters + special characters) and accidental word combinations (like "an al" which contains only letters).
isSpanningWordBoundary() logic to check if standalone portions contain both letters AND non-letter charactersfix: detect partial spacing profanity obfuscation - Profanity obfuscation using partial spacing is now correctly detected:
fix: detect partial spacing profanity obfuscation - Profanity obfuscation using partial spacing is now correctly detected:
"s hit" → detected as "shit""f uck" → detected as "fuck""t wat" → detected as "twat""fu c k" → detected as "fuck""tw a t" → detected as "twat"fix: convert byte offset to character offset for multibyte support - Fixed boundary checks to work correctly with multibyte characters (accented letters in French, German, etc.)
The isSpanningWordBoundary() method was refactored to check surrounding context instead of relying on heuristics about single-character parts. This ensures partial spacing obfuscation is detected while still preventing false positives like "This musicals hit".
Full Changelog: v3.1.6...v3.1.7
Fix accented character false positives ( #24 ): Added /u (PCRE_UTF8) flag to generated profanity regex patterns, preventing multi-byte UTF-8 character
/u (PCRE_UTF8) flag to generated profanity regex patterns, preventing multi-byte UTF-8 characters (e.g. ê, é) from being matched byte-by-byte and causing false positives on words like "tête" and "aré".check() entry point to sanitize non-UTF-8 strings before regex matching, preventing silent preg_match failures.check() no longer throws on empty/null strings ( #29 , #42 ) — Blasp::check() now accepts ?string and returns a clean result for empty or null input i
Fix false positive detection for common words ( #32 ) — Words like "assignment", "passion", "classroom", "passenger" were incorrectly flagged because
false_positives list covering substrings: ass, tit, cum, nig, rap, nob.Fix UUID flagged as profanity ( #23 ) — UUIDs like 6ec3e80f-...-144a2ef5800b were incorrectly flagged because 800b mapped to boob via character substi
6ec3e80f-...-144a2ef5800b were incorrectly flagged because 800b mapped to boob via character substitutions. Added an isInsideHexToken() guard that skips matches inside UUIDs, MD5/SHA hashes, and other long hex strings while leaving normal profanity detection intact.Fix circular substitution handling ( #35 ) — Replaced sequential preg_replace with a single-pass character walker that prevents circular substitutions
preg_replace with a single-pass character walker that prevents circular substitutions (e.g., French c→k and k→c) from producing malformed regex. Multi-char substitution values now use alternation instead of character classes. Language-specific substitutions are properly merged again.Nothing published for this version
Nothing published for this version
Custom mask character support with maskWith() method
maskWith() methodNothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
- initial release
Your coding agent can read these notes before it upgrades. Set up the MCP server →