NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Packagist · #4475 most downloaded on Packagist
A PHP library to parse Quill WYSIWYG editor deltas into HTML - flexible and extendible for custom elements.
Last release 1 months ago
30 Aug 2026
Release timing varies
gaps range from 2 weeks to 12 months
Nearly every release is documented
notes for 36 of 36 stable releases
Nothing withdrawn
no release was ever pulled
8 years old
37 releases · first in 2018
GHSA-q7wv-vg5w-462j Fixed a stored XSS vulnerability: URI schemes from delta attributes ( link , image , video ) are now validated against an allowlis…
link, image, video) are now validated against an allowlist before being written into rendered href/src attributes. Values with unsafe schemes (like javascript:) are neutralized: links point to #, images and videos are not rendered. If you relied on rendering custom URI schemes (e.g. ftp://), add them to the $safeSchemes property of the corresponding listener:$link = new Link();
$link->safeSchemes = ['http', 'https', 'mailto', 'tel', 'ftp'];
$lexer->overwriteListener(new Link(), $link);Full Changelog: 3.7.0...3.7.1
One column per quarter.
Add Size listener for font-size attribute support by @Copilot in #99
Full Changelog: 3.6.0...3.7.0
Fix heading rendering when combined with alignment attributes by @Copilot in #98
Full Changelog: 3.5.0...3.6.0
Bump symfony/process from 5.4.21 to 5.4.46 by @dependabot in #94
Full Changelog: 3.4.2...3.5.0
@shuedo made their first contribution in #88
Full Changelog: 3.4.1...3.4.2
3.4.1 (13. March 2024) #84 Allow align left as possible value.
left as possible value.Please be aware that this release may impact the way Quill data is displayed in your frontend. Checkout the upgrade document for more details.
Please be aware that this release may impact the way Quill data is displayed in your frontend. Checkout the upgrade document for more details.
3.3.1 (24. March 2023) #78 Fixed a bug where lists with empty contents would break all output. Full Changelog : 3.3.0...3.3.1
Full Changelog: 3.3.0...3.3.1
@tetreum made their first contribution in #77
registerListener() and overwriteListener().Full Changelog: 3.2.1...3.3.0
3.2.1 (1. November 2022) #74 Fixed missing support for nested lists #73 More automation and testing with rector and auto commit on PR's for csfixer an
3.2.0 (7. August 2022) #71 Added image width and height attributes to the image tag if available. #72 Raised from phpstan level 5 to 6
+ #68 Deprecated the magical getter $pick->$name in nadar\quill\Pick class, use $pick->optionValue($name) instead. + #64 Replaced deprecated public $i
$pick->$name in nadar\quill\Pick class, use $pick->optionValue($name) instead.Line with getter and setter methods getLine() and setLine($input).loadBuiltinListeneres() and renderListeneres().BlockListener->wrapElement() this will be added for your custom listeners as well, otherwise you'll need to add the newlines yourself.> This release contains breaks which might affect your application. Checkout the upgrade document for more details.
This release contains breaks which might affect your application. Checkout the upgrade document for more details.
+ #58 Renamed misspelled method loadBuiltinListeneres() to loadBuiltinListeners() and renderListeneres() to renderListeners(). The old methods are sti
loadBuiltinListeneres() to loadBuiltinListeners() and renderListeneres() to renderListeners(). The old methods are still available for backwards compatibility, but deprecated and will be removed in 3.0.+ #56 Provide new method to override existing listeners with overwriteListener().
overwriteListener().+ #53 Lists listener, check for type being an array for compatibility with Vanilla Forums.
+ #51 Fixed issue where images wrapped in italics renders as text instead of showing the image.
+ #49 Added Code Block Listener, generates ... enclosed output.
<pre><code>...</code></pre> enclosed output.+ #48 PHP 8 compatibility.
+ #42 Added PHP 8 Support. + #43 Moved CI from Travis to GitHub Actions. Added PHP 8 version in Test Scenario.
+ #41 Add option to configure Embed Video allow option.
allow option.+ #32 Added new wrapElement method to simplify building block listeners. + #30 List opening tag process has been simplified in order to support single
Add override functionality to links, allowing to customise their wrapper.
Add inline element to handle script attribute.
+ #25 Ensure that empty heading listeners won't destroy all upcoming elements.
+ #23 Add inline element to handle font attribute.
> This release contains breaks which might affect your application. Checkout the upgrade document for more details.
This release contains breaks which might affect your application. Checkout the upgrade document for more details.
escapeInput option by default in order to increase security.+ #13 Fixed bug when lists are interrupted with block level elements (e.g. videos) + #16 Fixed bug with sorting index of inline elements when using pr
+ #12 Fixed bug when using quill parser on windows platforms.
Added new debugInfo option for lines
+ #7 Makes sure input and attributes from delta is escaped before mixing it with html. Listeners should use $line->getInput() instead of $line->input
$line->getInput() instead of $line->input to read input. This will properly escape if it is not done already. Values from attributes should be passed through $line->getLexer()->escape(). See the Color listener for an example of both. Obviously, escaping should be skipped in case a listener is meant to output raw html.+ #6 Fixed bug in exception messaged. Added unit tests and improved message.
+ #5 Fixed a bug where paragraphs with attributes where not rendered (color attribute). Added new parameter to disable the rendering of attributes.
Added Image-Tag for image output.
Improve Video-Tag output (Remove frameborder, use youtube embed code allow tag).
+ First stable API release.
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →