NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Packagist · #555 most downloaded on Packagist
Client library for reCAPTCHA, a free service that protects websites from spam and abuse.
Last release 14 days ago
23 Sep 2026
Release timing varies
gaps range from 5 weeks to 2.9 years
Some releases are documented
notes for 9 of 19 stable releases
Nothing withdrawn
no release was ever pulled
12 years old
19 releases · first in 2015
2.1.0 is a backwards-compatible minor release in the 2.x series (PHP >=8.4 ) introducing immutable with*() builder methods on ReCaptcha , \JsonSeriali
2.1.0 is a backwards-compatible minor release in the 2.x series (PHP >=8.4) introducing immutable with*() builder methods on ReCaptcha, \JsonSerializable support on Response, configurable transport timeouts, ReCaptcha::SITE_VERIFY_URL_ALTERNATIVE, cURL handle connection reuse, unified HTTP status validation across all transports, and validation/security hardening.
with*() Builder Methods (ReCaptcha):
withExpectedHostname(), withExpectedApkPackageName(), withExpectedAction(), withScoreThreshold(), and withChallengeTimeout() methods that return a cloned ReCaptcha instance instead of mutating the instance in place—making ReCaptcha safe to share as a singleton in dependency injection containers and persistent worker runtimes (FrankenPHP, RoadRunner, Swoole, Laravel Octane) (#637).Response implements \JsonSerializable:
\JsonSerializable (jsonSerialize()) on ReCaptcha\Response so response objects can be passed directly to json_encode() (#636).int $timeout = 60 constructor parameter to CurlPost, Post, and SocketPost, and added CURLOPT_CONNECTTIMEOUT to CurlPost (#636).ReCaptcha::SITE_VERIFY_URL_ALTERNATIVE (https://www.recaptcha.net/recaptcha/api/siteverify) for environments where www.google.com is not accessible (#636).CurlPost now lazily initializes and reuses its CurlHandle across submit() calls for TLS session resumption and HTTP keep-alive (#637).200 status validation across CurlPost (CURLINFO_HTTP_CODE), Post (http_get_last_response_headers() with ignore_errors), and SocketPost so non-200 HTTP responses consistently return ReCaptcha::E_BAD_RESPONSE (#637).SocketPost now loops fwrite() to handle partial TLS socket writes and closes the socket handle cleanly on write failures (#637).#[\SensitiveParameter] to $secret in ReCaptcha::__construct() and RequestParameters::__construct() to prevent secret exposure in stack traces (#636).examples/ against DOM XSS, added server-side action allowlisting in examples/recaptcha-v3-verify.php, updated CSP connect-src, and added examples/recaptcha-v3-immutable.php (#636, #637).setScoreThreshold(0.0) null-coercion bypass when score is omitted (null) from the API response so it properly fails with ReCaptcha::E_SCORE_THRESHOLD_NOT_MET (#637).setChallengeTimeout() failing open when challenge_ts is empty or unparseable; it now fails closed with ReCaptcha::E_CHALLENGE_TIMEOUT (#637).error-codes in Response::fromJson() to ensure only string elements are retained (#636).2.0.0: Verified via roave/backward-compatibility-check.composer update google/recaptchaFull Changelog: 2.0.0...2.1.0
One column per quarter.
…API compatibility alongside recent transport security fixes.
Major release introducing strict PHP 8.4+ typing, immutable (readonly) response and parameter value objects, simplified transport constructors, and full PHP 8.5 compatibility.
Upgrading from
1.x? If you cannot yet adopt the breaking API changes below, remain on the^1.5release line (1.5.2), which preserves full1.4.2public API compatibility alongside recent transport security fixes.
declare(strict_types=1) and native scalar parameter, property, and return type declarations across ReCaptcha, Response, RequestParameters, and RequestMethod.Response & RequestParameters): Converted Response and RequestParameters to readonly classes with promoted constructor properties.CurlPost and SocketPost to accept ?string $siteVerifyUrl = null directly without intermediate wrapper objects.verify_peer / verify_peer_name in Post, added 60-second request timeouts, and enabled HTTP/1.1 response status parsing in SocketPost.curl_close() call in CurlPost so no deprecation notices are emitted on PHP 8.5 (#630, #632).SocketPost::submit() to ensure the open socket is closed if stream_set_timeout() fails.'0' Handling: Fixed ReCaptcha secret and response validation so the string '0' is treated as a non-empty input rather than discarded by empty().>=8.4): Requires PHP 8.4 or newer.RequestMethod::submit() Return Type: Custom implementations of ReCaptcha\RequestMethod must declare the native : string return type: public function submit(RequestParameters $params): string.ReCaptcha::verify(string $response, ?string $remoteIp = null): Response require string rather than null for $response (coalesce nullable framework request inputs via $token ?? '').readonly DTOs (Response & RequestParameters): Because PHP forbids non-readonly subclasses of readonly classes, PHPUnit::createMock(Response::class) cannot be used. In unit tests, instantiate new Response(true, ...) directly or mock the RequestMethod interface.RequestMethod\Curl & RequestMethod\Socket Wrappers: The Curl and Socket wrapper classes have been removed; new CurlPost($siteVerifyUrl) and new SocketPost($siteVerifyUrl) now take ?string $siteVerifyUrl = null as their first parameter.Full Changelog: 1.5.2...2.0.0
This maintenance release for the 1.x series ports the non-breaking transport security and proxy-compatibility improvements introduced during the 1.5 c
This maintenance release for the 1.x series ports the non-breaking transport security and proxy-compatibility improvements introduced during the 1.5 cycle onto the backward-compatible 1.4.2 / 1.5.1 public API, and adds automated backward-compatibility verification in CI.
RequestMethod\Post): Configured verify_peer and verify_peer_name under the ssl stream context (rather than http) so OpenSSL strictly verifies peer certificates and hostnames when using the file_get_contents() transport (#625).RequestMethod\CurlPost & RequestMethod\Post): Added explicit 60-second request timeouts (CURLOPT_TIMEOUT and http.timeout) so verification calls fail predictably if the upstream network hangs (#604).roave/backward-compatibility-check to GitHub Actions CI to automatically verify that future 1.x maintenance pull requests preserve 100% public API compatibility (#634 by @SNO7E-G).RequestMethod\SocketPost): Fixed SocketPost::submit() to accept both HTTP/1.0 200 OK and HTTP/1.1 200 OK status lines, preventing false bad-response errors when requests traverse HTTP/1.1 proxies (#616).1.4.2 and 1.5.1.Full Changelog: 1.5.1...1.5.2
Version 1.5.0 inadvertently introduced breaking changes to the public PHP API in a minor release ( #628 ), including strict parameter/return type hint…
1.5.1)Version 1.5.0 inadvertently introduced breaking changes to the public PHP API in a minor release (#628), including strict parameter/return type hints on public methods and RequestMethod::submit(), readonly modifiers on Response and RequestParameters, and the removal of the RequestMethod\Curl and RequestMethod\Socket wrapper classes.
1.5.11.4.2 public API compatibility (#633 by @SNO7E-G, reviewed by @acoulton):
ReCaptcha, Response, RequestParameters, and RequestMethod::submit().readonly from Response and RequestParameters so subclasses and test doubles (PHPUnit::createMock()) work as expected.RequestMethod\Curl and RequestMethod\Socket wrapper classes and legacy constructor parameter order (new CurlPost(?Curl $curl = null, ?string $siteVerifyUrl = null) and new SocketPost(?Socket $socket = null, ?string $siteVerifyUrl = null)).ReCaptcha::RESPONSE_KEY constant name in README.md.level: 2, treatPhpDocTypesAsCertain: false) for the 1.x compatibility line without requiring a baseline file.Note on
2.0.0: The strict type hints,readonlyDTOs, and constructor modernizations introduced in1.5.0have been preserved on the2.xbranch and will be released under major version2.0.0.
Remove Travis reference by @rowan-m in #591
Full Changelog: 1.4.1...1.4.2
Minor version bump for correct version reporting
Minor version bump for correct version reporting
Full Changelog: 1.4.0...1.4.1
Update to support for PHP 8.4 and 8.5
Full Changelog: 1.3.1...1.4.0
Nothing published for this version
Update to PHP8 support.
Update to PHP8 support.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
A lot of clean up, test improvements, and housekeeping but a few potentially breaks to backwards-compatibility for edge cases.
A lot of clean up, test improvements, and housekeeping but a few potentially breaks to backwards-compatibility for edge cases.
Full Changelog: 1.4.2...1.5
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →