PackageTrack
Sign in Get early access

paragonie/csp-builder

Easily add and update Content-Security-Policy headers for your project

v3.1.0 3.2M downloads/mo #2647 most downloaded on Packagist paragonie/csp-builder

What this package is like to depend on

Last release 5 days ago

18 Aug 2026

Ships fairly regularly

a new release about every 8 months

Some releases are documented

notes for 10 of 28 stable releases

Nothing withdrawn

no release was ever pulled

11 years old

28 releases · first in 2015

1 release in the last 12 months

see the full history below

Release timeline

28 releases · Jun 2015 to Aug 2026
2016 2017 2018 2019 2020 2021 2022 2023 2024 2025 2026
Release Pre-release

Releases

latest 28
  1. v3.1.0 18 Aug 2026
    Release notes

    What's Changed

    New Contributors

    Full Changelog: v3.0.2...v3.1.0

    Open source →
  2. v3.0.2 03 Jan 2025
    Release notes

    What's Changed

    New Contributors

    Full Changelog: v3.0.1...v3.0.2

    Open source →
  3. v3.0.1 08 May 2024
    Release notes
    • #77 - prevent duplicate policies
    • Updated dependencies
    Open source →
  4. v3.0.0 18 Dec 2023
    Release notes

    What's Changed

    • PHP <7.4 is not supported in this new major version!
      • The changes in #70 created a dependency conflict with PHP <7.4.
    • Add a CSP header parser (CSPBuilder::fromHeader) by @fritzmg in #74
    • un-deprecate frame-src by @fritzmg in #76
    • Generate nonce also when only default-src policy is applied by @fritzmg in #65
    • Add PoC of report-to header by @Firesphere in #70

    Full Changelog: v2.9.0...v3.0.0

    Open source →
  5. v2.9.0 24 May 2023
    Release notes

    What's Changed

    New Contributors

    Full Changelog: v2.8.1...v2.9.0

    Open source →
  6. v2.8.1 26 Mar 2023
    Release notes

    What's Changed

    New Contributors

    Full Changelog: v2.8.0...v2.8.1

    Open source →
  7. v2.8.0 15 Dec 2022
    Release notes

    Prevent semicolon or CLRF injection. See 1a1a85f for details.

    CSP-Builder is a developer tool. It is not meant to be used with user input.

    However, the ability to inject CSP directives or additional headers violates the principle of least astonishment.

    This was reported via user demonia on HackerOne.

    Open source →
  8. v2.7.0 01 Oct 2022
    Release notes
    • CI: Build/test on PHP 8.2
    • Add support for "unsafe-hashes" directive
    Open source →
  9. v2.6.0 07 Sep 2021
    Release notes
    • #56 You can now save policies as JSON strings or to disk (reported in #39)
    • #55 Allow hooks before writing output to disk
    • #54 Allow https: scheme sources
    • #51 Allow sample report directive
    • Fixed #23 -- duplicate directives are now prevented
    • Implemented #52
    Open source →
  10. v2.5.0 02 Sep 2020
    Release notes
    • Consistently invalidate the compiled CSP cache.
    • Update PHPUnit, etc.
    • Dropped support for PHP 7.0. You can continue to install 2.4.0, but we will not be backporting patches into the old version. PHP 7.0 is EOL, please upgrade to 7.4 or newer.
    Open source →
  11. v2.4.0 19 Oct 2019

    Nothing published for this version

  12. v2.3.1 03 Jan 2019

    Nothing published for this version

  13. v2.3.0 20 Nov 2017

    Nothing published for this version

  14. v2.2.0 08 Nov 2017

    Nothing published for this version

  15. v2.1.0 24 Jul 2017

    Nothing published for this version

  16. v2.0.1 01 Nov 2016

    Nothing published for this version

  17. v2.0.0 09 Apr 2016

    Nothing published for this version

  18. v1.4.0 09 Nov 2017

    Nothing published for this version

  19. v1.3.3 01 Nov 2016

    Nothing published for this version

  20. v1.3.1 17 Feb 2016

    Nothing published for this version

  21. v1.3.0 01 Feb 2016

    Nothing published for this version

  22. v1.2.4 30 Jan 2016

    Nothing published for this version

  23. v1.2.3 29 Jan 2016

    Nothing published for this version

  24. v1.2.2 20 Jan 2016

    Nothing published for this version

  25. v1.2.1 13 Jan 2016

    Nothing published for this version

  26. v1.2.0 03 Jan 2016

    Nothing published for this version

  27. v1.1.0 02 Jan 2016

    Nothing published for this version

  28. 1.0.0 16 Jun 2015

    Nothing published for this version

Every package, every release, already written down.

The archive is open and free. Watching your own project is what we are building next.

Browse the archive