NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Packagist · #2583 most downloaded on Packagist
Searchable field-level encryption library for relational databases
Last release 7 months ago
05 Mar 2026
Release timing varies
gaps range from 3 weeks to 1.1 years
Rarely documented
notes for 10 of 41 stable releases
Nothing withdrawn
no release was ever pulled
8 years old
41 releases · first in 2018
Update CI by @paragonie-security in #114
Full Changelog: v4.9.0...v4.10.0
Ignore tests, workflows with export-ignore by @erikn69 in #111
export-ignore by @erikn69 in #111Full Changelog: v4.8.0...v4.9.0
One column per quarter.
New Feature : If you use a StaticBlindIndexKeyProvider interface for your Key Providers, you can now designate a specific "tenant" identifier to be st
New Feature: If you use a StaticBlindIndexKeyProvider interface for your Key Providers, you can now designate a specific "tenant" identifier to be static and used for Blind Index root key derivation. This works with EncryptedRow and EncryptedMultiRows.
Full Changelog: v4.7.0...v4.8.0
Added a new AAD class, which allows users to bind an encrypted field to the contents of multiple plaintext fields. This class can be used in the same
AAD class, which allows users to bind an encrypted field to the contents of multiple plaintext fields. This class can be used in the same place where a field name or literal value was used previously.EncryptedFile now accepts an optional AAD param, which binds the file's contents to the AAD value.Here's a quick example of the old API, then a diff to use the new AAD features:
<?php
use ParagonIE\CipherSweet\CipherSweet;
use ParagonIE\CipherSweet\EncryptedMultiRows;
/** @var CipherSweet $engine */
$multiRowEncryptor = new EncryptedMultiRows($engine);
$multiRowEncryptor
->addTextField('table1', 'field1')
->addIntegerField('table1', 'field2')
->addFloatField('table1', 'field3')
->addOptionalBooleanField('table1', 'field4')
->addTextField('table2', 'foo')
->addTextField('table3', 'bar');
$encrypted = $multiRowEncryptor->encryptManyRows([
'table1' => ['field1' => 'hello world', 'field2' => 42, 'field3' => 3.1416],
'table2' => ['id' => 3, 'foo' => 'joy'],
'table3' => ['foo' => 'coy'],
]);And here's how to easily enable to new features:
$multiRowEncryptor = new EncryptedMultiRows($engine);
$multiRowEncryptor
+ ->setAutoBindContext(true)
+ ->setPrimaryKeyColumn('table2', 'id')
->addTextField('table1', 'field1')With this change, every encrypted field is explicitly cryptographically bound to its context (table name, field name) with no further action needed from the developer.
Additionally, table2 is cryptographically bound to its primary key (id). This has two consequences:
That second point is the main reason why we are not enabling it by default. (Also, we'd kind of need to know your primary key naming convention, which we cannot know for everyone that uses this library.)
We will update the documentation as soon as possible.
Allow constant_time_encoding v3
Update CI configuration by @paragonie-security in #100
Full Changelog: v4.5.1...v4.6.0
More helpful exception message on NULL values. See #95 , #92 , #93 .
More helpful exception message on NULL values. See #95, #92, #93.
If you do not declare a field optional, it generally will not accept NULL as a value on encrypt. Boolean is the exception to this rule (for backwards compat).
However, non-optional fields (even booleans) must have a ciphertext on the decrypt path.
Encrypt:
TYPE_BOOLEAN + (null) -> ciphertext
TYPE_OPTIONAL_BOOLEAN + (null) -> ciphertext
Decrypt:
TYPE_BOOLEAN + (null) -> TypeError
TYPE_OPTIONAL_BOOLEAN + (null) -> null
Booleans are the weird ones, though.
Encrypt:
TYPE_TEXT + (null) -> TypeError
TYPE_OPTIONAL_TEXT + (null) -> null
Decrypt:
TYPE_TEXT + (null) -> TypeError
TYPE_OPTIONAL_BOOLEAN + (null) -> null
Every other type doesn't tolerate null implicitly. This behavior is because of a very early design decision with boolean types.
What's Changed #92 Explicit support for optional field types #88 Support json field map templating Full Changelog : v4.4.0...v4.5.0
Full Changelog: v4.4.0...v4.5.0
What's Changed Feature: Extension Keys in #86 Full Changelog : v4.3.0...v4.4.0
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
[v3.x] Update CI configuration, dependencies by @paragonie-security in #101
Full Changelog: v3.4.0...v3.4.1
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →