NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Packagist · #4246 most downloaded on Packagist
A CakePHP plugin containing lots of useful and reusable tools
Last release 2 months ago
18 Jul 2026
Release timing varies
gaps range from 1 weeks to 4 months
Rarely documented
notes for 10 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
13 years old
144 releases · first in 2013
DateTime::lengthOfTime() / relLengthOfTime() : automatic mode now scales units up through weeks, months and years, capped by a new accuracy option (de
DateTime::lengthOfTime() / relLengthOfTime(): automatic mode now scales units up through weeks, months and years, capped by a new accuracy option (default 2), e.g. 1 Week, 3 Days or 11 Years, 3 Months. relLengthOfTime() computes the difference calendar-exact via DateInterval (months/years respect calendar lengths and leap years) and gains a from option for a custom reference point. Relative unit words are translated with a relative msgctxt for grammatically correct wording (e.g. German dative: Vor 4 Tagen). Singular output fixed (1 Day instead of 1 Days), zero units are skipped. Legacy explicit-format engine kept for BC and extended with Y/M/W/w characters. #338GravatarHelper: add a hashAlgo option (default sha256, md5 supported) so callers can restore Gravatar's pre-2024 MD5 identifier for legacy accounts. Without it, the SHA-256 switch silently changes the generated default avatar (identicon, monsterid, ...) for every account that has no real Gravatar image. Unknown values fall back to sha256 and the option never leaks into the URL or img attributes. #336Full Changelog: 3.13.1...3.13.2
One column per quarter.
Restore the entity generic on the Table base class, so IdeHelper-generated Table subclass annotations and entity-typed finder return types resolve und
Table base class, so IdeHelper-generated Table subclass annotations and entity-typed finder return types resolve under PHPStan again (#334)<4.0.0), so the plugin can no longer be paired with an incompatible authentication version (#335)Full Changelog: 3.13.0...3.13.1
Honor camelCase DataPreparation.noTrim config key
Full Changelog: 3.12.9...3.13.0
Gravatar now uses SHA-256, encryption is idempotent, and pregMatch() no longer splices UTF-8 incorrectly
pregMatch() no longer splices UTF-8 incorrectly (#326)PasswordHasherFactory now resolves app- and plugin-provided password hashers instead of being locked to the Tools plugin prefix, while still keeping the built-in Default hasher safe from being silently shadowed (#328)Full Changelog: 3.12.8...3.12.9
Stop rendering the title attribute unescaped in FormatHelper::neighbors() . The link options forced escape => false , which in CakePHP HtmlHelper disa
title attribute unescaped in FormatHelper::neighbors(). The link options forced escape => false, which in CakePHP HtmlHelper disables escaping of both the link text and attribute values, so the title attribute rendered raw from arbitrary DB content (XSS surface). Switched to escapeTitle => false so the icon HTML stays in the link text but attributes escape normally. Regression test covers <script> and &" payloads in title-field values.Tools\Model\Table\Table::_validUrl(). Both ternary branches returned 'HTTP', and the [(200|301|302)] regex used a character class instead of an alternation — so it matched any status line containing one of ( 0 1 2 3 |). Replaced with a hardcoded HTTP/ prefix and real (200|301|302) / (404|999) alternations.<select> no longer carries an inline onchange="window.location.href=this.value" handler — replaced with a data-paginator-navigate attribute and a small delegated change listener at the bottom of the element. The accompanying <script> block carries a CSP nonce sourced from the cspNonce request attribute, so apps with a strict script-src 'self' 'nonce-...' policy can run it; falls back gracefully when no nonce is set. (Inline event handlers are blocked under strict CSP without unsafe-inline / unsafe-hashes, and the nonce directive does not cover them per the CSP spec — removing the attribute entirely is the only portable fix.)__() calls in user-facing strings to __d('tools', ...) so translations resolve through the plugin's own i18n domain instead of leaking into the host app's default domain. Affects four static labels in templates/Admin/Helper/{chars,bitmasks}.php and four dynamic title/icon strings in IconCollection, CommonHelper, and FormatHelper. Also refreshes resources/locales/tools.pot (the previous POT was ~6 years stale); existing language files are left for translators to msgmerge against the new POT.Full Changelog: 3.12.7...3.12.8
Enforce validity window in TokensTable::useKey() . Previously an unused token stayed redeemable past its configured validity until the garbage collect
TokensTable::useKey(). Previously an unused token stayed redeemable past its configured validity until the garbage collector ran — a real gap for magic-login, email-verification, and password-reset style flows. useKey() now rejects tokens where created < now - validity unless marked unlimited.TEntity template through Tools\Model\Table\Table so subclasses can type their entity for PHPStan. Requires dereuromark/cakephp-shim 3.8.4+ and CakePHP 5.3.4+.Full Changelog: 3.12.6...3.12.7
Fix autoPrefixUrl() calling urlExists() with invalid URL when input already has https:// protocol
autoPrefixUrl() calling urlExists() with invalid URL when input already has https:// protocolFull Changelog: 3.12.5...3.12.6
Add timeout to urlExists() cURL request
Add timeout to urlExists() cURL request (#315)
CURLOPT_TIMEOUT (5s) - total request timeoutCURLOPT_CONNECTTIMEOUT (3s) - connection timeoutCURLOPT_FOLLOWLOCATION with MAXREDIRS (3) - follow redirectscurl_close() - properly clean up handleAdd timeout to remaining HTTP requests (#316)
Utility::urlExists() fallback: 5s stream context timeoutUtility::getHeaderFromUrl(): 5s timeoutMime::getMimeTypeByUrl(): 5s timeoutMessage::_readFile(): 10s timeoutFix autoPrefixUrl() calling urlExists() with invalid URL
https:// are now returned as-ishttp:// are properly upgraded by replacing the prefixhttps://https://example.comThis prevents requests from hanging indefinitely when servers don't respond.
Use ServerRequest::clientIp() instead of env('REMOTE_ADDR') for proper proxy header handling
ServerRequest::clientIp() instead of env('REMOTE_ADDR') for proper proxy header handlingFull Changelog: 3.12.3...3.12.4
Fix page action URLs to use dasherized format instead of camelCase
scope and onDirty options to SluggedBehaviorFull Changelog: 3.12.2...3.12.3
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →