NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Packagist · #1600 most downloaded on Packagist
The CodeIgniter framework v4
Last release 3 months ago
07 Jul 2026
Ships fairly regularly
a new release about every 2 months
Rarely documented
notes for 10 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
8 years old
79 releases · first in 2018
See the changelog: https://github.com/codeigniter4/CodeIgniter4/blob/develop/CHANGELOG.md
CodeIgniter 4.7.4 release.
See the changelog: https://github.com/codeigniter4/CodeIgniter4/blob/develop/CHANGELOG.md
Full Changelog: codeigniter4/CodeIgniter4@v4.7.3...v4.7.4
IncomingRequest: HTTPS detection via client-supplied headers was fixed.
IncomingRequest::isSecure() now trusts the X-Forwarded-Proto and
Front-End-Https headers only when the request comes from a trusted proxy
configured in Config\App::$proxyIPs.
See the Security advisory GHSA-7wmf-pw8j-mc78 <https://github.com/codeigniter4/CodeIgniter4/security/advisories/GHSA-7wmf-pw8j-mc78>_
for more information.
Query Builder: Fixed a SQL injection vulnerability in deleteBatch().
When deleteBatch() was used together with where() conditions, the
bound values from the WHERE clause were substituted into the generated SQL
with their escape flag ignored, so they were never escaped or quoted. The
WHERE binds are now escaped in the same way as a regular delete().
See the Security advisory GHSA-c9w5-rwh3-7pm9 <https://github.com/codeigniter4/CodeIgniter4/security/advisories/GHSA-c9w5-rwh3-7pm9>_
for more information.
UploadedFile: UploadedFile::move() now sanitizes the client-provided
filename when called without a second argument. Previously, the unsanitized
client filename was used as the default, allowing path traversal sequences
(e.g. ../../public/shell.php) to write the uploaded file outside the
intended directory. A name explicitly passed as the second argument is not
sanitized and remains the caller's responsibility.
See the Security advisory GHSA-hhmc-q9hp-r662 <https://github.com/codeigniter4/CodeIgniter4/security/advisories/GHSA-hhmc-q9hp-r662>_
for more information.
Validation: The is_image and mime_in file upload validation rules
now also verify non-empty client filename extensions. Previously, these rules
classified an upload solely by its content-derived MIME type, so a file with a
dangerous client extension (for example, a .php file prepended with image
magic bytes) could pass validation while keeping its original extension on
disk.
See the Security advisory GHSA-mmj4-63m4-r6h5 <https://github.com/codeigniter4/CodeIgniter4/security/advisories/GHSA-mmj4-63m4-r6h5>_
for more information.
The is_image rule now rejects uploads when a non-empty client filename
extension is not an image extension. The mime_in rule now rejects uploads
when a non-empty client filename extension does not match the detected file
content, matching the same extension/content agreement used by ext_in.
Files uploaded without any extension (such as JavaScript Blob uploads)
are still accepted, since the rules validate the file content.
MockInputOutput by @paulbalandan in https://github.com/codeigniter4/CodeIgniter4/pull/10307spark lang:find by @paulbalandan in https://github.com/codeigniter4/CodeIgniter4/pull/10308InvalidChars arrays by @gr8man in https://github.com/codeigniter4/CodeIgniter4/pull/10303--return entity) by @xgrind in https://github.com/codeigniter4/CodeIgniter4/pull/10232env() TypeError for non-string $_SERVER values + esc() fixes by @gr8man in https://github.com/codeigniter4/CodeIgniter4/pull/10305getPostGet() and getGetPost() by @michalsn in https://github.com/codeigniter4/CodeIgniter4/pull/10362Image original dimension types to int by @michalsn in https://github.com/codeigniter4/CodeIgniter4/pull/10326download() method by @gr8man in https://github.com/codeigniter4/CodeIgniter4/pull/10330mixed with more specific types by @paulbalandan in https://github.com/codeigniter4/CodeIgniter4/pull/10345prepQuotedPrintable() with hash lookup and int-length tracking by @gr8man in https://github.com/codeigniter4/CodeIgniter4/pull/10344array phpdocs for CLI by @paulbalandan in https://github.com/codeigniter4/CodeIgniter4/pull/10354_processForeignKeys() string allocations and loop invariants by @gr8man in https://github.com/codeigniter4/CodeIgniter4/pull/10351One column per quarter.
See the changelog: https://github.com/codeigniter4/CodeIgniter4/blob/develop/CHANGELOG.md
CodeIgniter 4.7.3 release.
See the changelog: https://github.com/codeigniter4/CodeIgniter4/blob/develop/CHANGELOG.md
Full Changelog: codeigniter4/CodeIgniter4@v4.7.2...v4.7.3
Validation: Uploaded file extension validation bypass in ext_in rule
The ext_in file upload validation rule now validates the client filename extension and verifies that it
matches the detected MIME type. Previously, ext_in only checked the MIME-derived guessed extension, so
a file with a mismatched client extension could pass validation.
See the GHSA-2gr4-ppc7-7mhx security advisory for more information. Credits to @z3moo and @teebow1e for reporting the issue.
register() so unregister() can remove them by @michalsn in https://github.com/codeigniter4/CodeIgniter4/pull/10097command() by @paulbalandan in https://github.com/codeigniter4/CodeIgniter4/pull/10099CLI::write() and CLI::error() by @paulbalandan in https://github.com/codeigniter4/CodeIgniter4/pull/10106env command with options only would not throw by @paulbalandan in https://github.com/codeigniter4/CodeIgniter4/pull/10114CLI::generateDimensions() when stdin is not a TTY by @paulbalandan in https://github.com/codeigniter4/CodeIgniter4/pull/10124Time::createFromTimestamp locale-independent by @michalsn in https://github.com/codeigniter4/CodeIgniter4/pull/10151decrement() method by @patel-vansh in https://github.com/codeigniter4/CodeIgniter4/pull/10155increment() and decrement() methods not working for numeric columns by @patel-vansh in https://github.com/codeigniter4/CodeIgniter4/pull/10172key:generate command by @paulbalandan in https://github.com/codeigniter4/CodeIgniter4/pull/10183Language::getLine() by @paulbalandan in https://github.com/codeigniter4/CodeIgniter4/pull/10189Entity::normalizeValue() must handle UnitEnum before toArray() by @maniaba in https://github.com/codeigniter4/CodeIgniter4/pull/10137--host option in serve command by @paulbalandan in https://github.com/codeigniter4/CodeIgniter4/pull/10203logs:clear command by @paulbalandan in https://github.com/codeigniter4/CodeIgniter4/pull/10090debugbar:clear command by @paulbalandan in https://github.com/codeigniter4/CodeIgniter4/pull/10093--do-not-cache-result to prevent shared cache corruption by @michalsn in https://github.com/codeigniter4/CodeIgniter4/pull/10098cache:clear command by @paulbalandan in https://github.com/codeigniter4/CodeIgniter4/pull/10094-h option of routes command as --handler by @paulbalandan in https://github.com/codeigniter4/CodeIgniter4/pull/10113--handler to --sort-by-handler for routes by @paulbalandan in https://github.com/codeigniter4/CodeIgniter4/pull/10125ClearLogs::execute() error message is misleading after interactive 'n' by @paulbalandan in https://github.com/codeigniter4/CodeIgniter4/pull/10126FileLocator::listFiles() by @paulbalandan in https://github.com/codeigniter4/CodeIgniter4/pull/10142See the changelog: https://github.com/codeigniter4/CodeIgniter4/blob/develop/CHANGELOG.md
CodeIgniter 4.7.2 release.
See the changelog: https://github.com/codeigniter4/CodeIgniter4/blob/develop/CHANGELOG.md
Full Changelog: codeigniter4/CodeIgniter4@v4.7.1...v4.7.2
See the changelog: https://github.com/codeigniter4/CodeIgniter4/blob/develop/CHANGELOG.md
CodeIgniter 4.7.1 release.
See the changelog: https://github.com/codeigniter4/CodeIgniter4/blob/develop/CHANGELOG.md
Full Changelog: codeigniter4/CodeIgniter4@v4.7.0...v4.7.1
.env overrides by @michalsn in https://github.com/codeigniter4/CodeIgniter4/pull/10037savePath check in MemcachedHandler constructor by @michalsn in https://github.com/codeigniter4/CodeIgniter4/pull/9941updateBatch() when updateOnlyChanged is true by @michalsn in https://github.com/codeigniter4/CodeIgniter4/pull/9944appOverridesFolder config in View by @michalsn in https://github.com/codeigniter4/CodeIgniter4/pull/9958BaseConnection::callFunction() by @michalsn in https://github.com/codeigniter4/CodeIgniter4/pull/9959Model::chunk() by @michalsn in https://github.com/codeigniter4/CodeIgniter4/pull/9961FeatureTestTrait::withRoutes() may throw all sorts of errors on invalid HTTP methods by @paulbalandan in https://github.com/codeigniter4/CodeIgniter4/pull/10004$headers param in FeatureTestTrait::withHeaders() by @michalsn in https://github.com/codeigniter4/CodeIgniter4/pull/9932CodeIgniter::CI_VERSION by @paulbalandan in https://github.com/codeigniter4/CodeIgniter4/pull/9951builds next option by @neznaika0 in https://github.com/codeigniter4/CodeIgniter4/pull/9946__unserialize instead of __wakeup in TimeTrait by @paulbalandan in https://github.com/codeigniter4/CodeIgniter4/pull/9957Exceptions::isImplicitNullableDeprecationError by @paulbalandan in https://github.com/codeigniter4/CodeIgniter4/pull/9965Security test fail by itself by @paulbalandan in https://github.com/codeigniter4/CodeIgniter4/pull/9969See the changelog: https://github.com/codeigniter4/CodeIgniter4/blob/develop/CHANGELOG.md
CodeIgniter 4.7.0 release.
See the changelog: https://github.com/codeigniter4/CodeIgniter4/blob/develop/CHANGELOG.md
Full Changelog: codeigniter4/CodeIgniter4@v4.6.5...v4.7.0
regex_match rule by @michalsn in https://github.com/codeigniter4/CodeIgniter4/pull/9597deleteMatching method definition in CacheInterface by @yassinedoghri in https://github.com/codeigniter4/CodeIgniter4/pull/9809toRawArray() by @michalsn in https://github.com/codeigniter4/CodeIgniter4/pull/9841PageCache filter by @michalsn in https://github.com/codeigniter4/CodeIgniter4/pull/9856key handling in encryption by @michalsn in https://github.com/codeigniter4/CodeIgniter4/pull/9868QueryInterface by @paulbalandan in https://github.com/codeigniter4/CodeIgniter4/pull/9892remember() to CacheInterface by @datamweb in https://github.com/codeigniter4/CodeIgniter4/pull/9875#[ReturnTypeWillChange] by @paulbalandan in https://github.com/codeigniter4/CodeIgniter4/pull/9900ImageMagickHandler to rely solely on the PHP imagick extension by @michalsn in https://github.com/codeigniter4/CodeIgniter4/pull/9526Time::addCalendarMonths() and Time::subCalendarMonths() methods by @christianberkman in https://github.com/codeigniter4/CodeIgniter4/pull/9528clearMetadata() method to provide privacy options when using imagick handler by @michalsn in https://github.com/codeigniter4/CodeIgniter4/pull/9538dns_cache_timeout for option CURLRequest by @ddevsr in https://github.com/codeigniter4/CodeIgniter4/pull/9553fresh_connect options to CURLRequest by @ddevsr in https://github.com/codeigniter4/CodeIgniter4/pull/9559CookieInterface::EXPIRES_FORMAT to use date format per RFC 7231 by @paulbalandan in https://github.com/codeigniter4/CodeIgniter4/pull/9563CURLRequest by @ddevsr in https://github.com/codeigniter4/CodeIgniter4/pull/9557JSONFormatter max depth by @ddevsr in https://github.com/codeigniter4/CodeIgniter4/pull/9585.env directory path by @totoprayogo1916 in https://github.com/codeigniter4/CodeIgniter4/pull/9631insertBatch() and updateBatch() respect model rules by @michalsn in https://github.com/codeigniter4/CodeIgniter4/pull/9708UserAgent class by @michalsn in https://github.com/codeigniter4/CodeIgniter4/pull/9782async & persistent options to Cache Redis by @ddevsr in https://github.com/codeigniter4/CodeIgniter4/pull/9792ResponseCache by @sk757a in https://github.com/codeigniter4/CodeIgniter4/pull/9855Maximum call stack size exceeded on client-managed requests by @datamweb in https://github.com/codeigniter4/CodeIgniter4/pull/9852isPast() and isFuture() time convenience methods by @datamweb in https://github.com/codeigniter4/CodeIgniter4/pull/9861app/Views directory by @datamweb in https://github.com/codeigniter4/CodeIgniter4/pull/9860Superglobals implementation by @michalsn in https://github.com/codeigniter4/CodeIgniter4/pull/9858persistent config item to redis handler Session by @ddevsr in https://github.com/codeigniter4/CodeIgniter4/pull/9793script-src-elem directive by @mark-unwin in https://github.com/codeigniter4/CodeIgniter4/pull/9722report-to directive by @paulbalandan in https://github.com/codeigniter4/CodeIgniter4/pull/9910Email by @ddevsr in https://github.com/codeigniter4/CodeIgniter4/pull/9570DATE_RFC7231 constant by @paulbalandan in https://github.com/codeigniter4/CodeIgniter4/pull/9657curl_close has no effect since PHP 8.0 by @ddevsr in https://github.com/codeigniter4/CodeIgniter4/pull/9683finfo_close has no effect since PHP 8.1 by @ddevsr in https://github.com/codeigniter4/CodeIgniter4/pull/9684imagedestroy has no effect since PHP 8.0 by @ddevsr in https://github.com/codeigniter4/CodeIgniter4/pull/9688FILTER_DEFAULT for filter_*() by @ddevsr in https://github.com/codeigniter4/CodeIgniter4/pull/9699PHP 8.2 by @ddevsr in https://github.com/codeigniter4/CodeIgniter4/pull/9701SensitiveParameter attribute to methods dealing with sensitive info by @paulbalandan in https://github.com/codeigniter4/CodeIgniter4/pull/9710BaseModel, Model and dependencies by @neznaika0 in https://github.com/codeigniter4/CodeIgniter4/pull/9830Entity class by @neznaika0 in https://github.com/codeigniter4/CodeIgniter4/pull/9878$db->connID to false by @paulbalandan in https://github.com/codeigniter4/CodeIgniter4/pull/9891ContentSecurityPolicy by @paulbalandan in https://github.com/codeigniter4/CodeIgniter4/pull/9904CodeIgniter\HTTP\ContentSecurityPolicy::$nonces since never used by @paulbalandan in https://github.com/codeigniter4/CodeIgniter4/pull/9905For the changelog of v4.6, see CHANGELOG_4.6.md.<br/> For the changelog of v4.5, see CHANGELOG_4.5.md.<br/> For the changelog of v4.4, see CHANGELOG_4.4.md.<br/> For the changelog of v4.3, see CHANGELOG_4.3.md.<br/> For the changelog of v4.2, see CHANGELOG_4.2.md.<br/> For the changelog of v4.1, see CHANGELOG_4.1.md.<br/> For the changelog of v4.0, see CHANGELOG_4.0.md.
See the changelog: https://github.com/codeigniter4/CodeIgniter4/blob/develop/CHANGELOG.md
CodeIgniter 4.6.5 release.
See the changelog: https://github.com/codeigniter4/CodeIgniter4/blob/develop/CHANGELOG.md
Full Changelog: codeigniter4/CodeIgniter4@v4.6.4...v4.6.5
See the changelog: https://github.com/codeigniter4/CodeIgniter4/blob/develop/CHANGELOG.md
CodeIgniter 4.6.4 release.
See the changelog: https://github.com/codeigniter4/CodeIgniter4/blob/develop/CHANGELOG.md
Full Changelog: codeigniter4/CodeIgniter4@v4.6.3...v4.6.4
See the changelog: https://github.com/codeigniter4/CodeIgniter4/blob/develop/CHANGELOG.md
CodeIgniter 4.6.3 release.
See the changelog: https://github.com/codeigniter4/CodeIgniter4/blob/develop/CHANGELOG.md
Full Changelog: codeigniter4/CodeIgniter4@v4.6.2...v4.6.3
See the changelog: https://github.com/codeigniter4/CodeIgniter4/blob/develop/CHANGELOG.md
CodeIgniter 4.6.2 release.
See the changelog: https://github.com/codeigniter4/CodeIgniter4/blob/develop/CHANGELOG.md
Full Changelog: codeigniter4/CodeIgniter4@v4.6.1...v4.6.2
See the changelog: https://github.com/codeigniter4/CodeIgniter4/blob/develop/CHANGELOG.md
CodeIgniter 4.6.1 release.
See the changelog: https://github.com/codeigniter4/CodeIgniter4/blob/develop/CHANGELOG.md
Full Changelog: codeigniter4/CodeIgniter4@v4.6.0...v4.6.1
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →