NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Packagist · #1609 most downloaded on Packagist
📝 Nette Forms: generating, validating and processing secure forms in PHP. Handy API, fully customizable, server & client side validation and mature design.
Last release 3 months ago
28 Jun 2026
Release timing varies
gaps range from 2 weeks to 6 months
Rarely documented
notes for 8 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
12 years old
68 releases · first in 2014
…, and a round of housekeeping clears out long-deprecated APIs. Please test and report anything that breaks for you.
The headline of 3.3 is CSRF protection that the browser handles for you – no token, no cookie, no server-side state, and it holds even against XSS. On top of that, the confusing {formContext} / {formContainer} pair collapses into a single {form scope}, you can finally nest forms with {form detached}, and a round of housekeeping clears out long-deprecated APIs. Please test and report anything that breaks for you.
Sec-Fetch-Site header instead of the old SameSite cookie. The previous mechanism trusted submissions from any subdomain of the same site; the new one demands an exact origin match (scheme + host + port).setValues() / setDefaults() now expect iterable|stdClass.RadioList / CheckboxList: getControlPart() and getLabelPart() throw on an invalid item key instead of silently returning a nonsensical result.DataClassGenerator, LatteRenderer, getValues(true) (use getValues('array')), and the $default parameter of getOption() (use the ?? operator), negative validation rules{form scope name} – one tag to replace the easily-confused {formContext} and {formContainer}. It pushes the form onto the stack without emitting <form>, resolving the name relatively to an active form when there is one, otherwise from the top level.{form detached name} – nest forms at last. HTML forbids nested <form> tags, so detached emits an empty <form></form> up front and links every control back to it via the HTML5 form="..." attribute, no matter where they sit in the DOM.addSubmit() accepts an $onSubmit callback – attach a click handler right when you create the button, without a separate ->onClick[] =.{form} arguments – write {form name, attr=val} instead of {form name attr=val}, freeing keywords like scope/detached next to the name.One column per quarter.
Nothing published for this version
A maintenance-focused release that tightens type safety across the whole codebase, modernizes the JavaScript test stack, and turns static analysis int
A maintenance-focused release that tightens type safety across the whole codebase, modernizes the JavaScript test stack, and turns static analysis into a non-negotiable part of the build. No API changes – just a more solid foundation under the hood.
Container, BaseControl, Validator, Rules, Form and friends, so PHPStan (and your IDE) see the real shape of thingsallowCrossOrigin() for clarityCheckboxList, RadioList::getControl() return empty element when has no items
RadioList::getControl() return empty element when has no itemsoptimized global function calls
SelectBox: correctly selects prompt #343
Container::addEmail() : added $maxLength=255 #303
Container::addEmail(): added $maxLength=255 #303getValue() instead of loadHttpData()__call() nette/utils#315Container::getValue() supports conversion to enums [Close #337 ]
Container::getValue() supports conversion to enums [Close #337]setNullable()Helpers::getSupportedTypes() returns array #332netteForms: reimplemented compact transmission mode via formdata event
isNullable()Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →