NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Packagist · #2516 most downloaded on Packagist
Easily add and update Content-Security-Policy headers for your project
Last release 1 months ago
18 Aug 2026
Ships fairly regularly
a new release about every 8 months
Some releases are documented
notes for 10 of 28 stable releases
Nothing withdrawn
no release was ever pulled
11 years old
28 releases · first in 2015
Add getPolicies method to CSPBuilder class by @jahidulpabelislam in #80
Full Changelog: v3.0.2...v3.1.0
One column per quarter.
add updates for PHP 8.4 by @cliffordvickrey in #78
Full Changelog: v3.0.1...v3.0.2
#77 - prevent duplicate policies Updated dependencies
un-deprecate frame-src by @fritzmg in #76
CSPBuilder::fromHeader) by @fritzmg in #74frame-src by @fritzmg in #76default-src policy is applied by @fritzmg in #65Full Changelog: v2.9.0...v3.0.0
Add support for psr/http-message v2 by @internalsystemerror in #73
psr/http-message v2 by @internalsystemerror in #73Full Changelog: v2.8.1...v2.9.0
Add 'url' type value for report-uri by @danieltott in #61
plugin-types generation by @fritzmg in #69Full Changelog: v2.8.0...v2.8.1
Prevent semicolon or CLRF injection. See 1a1a85f for details.
Prevent semicolon or CLRF injection. See 1a1a85f for details.
CSP-Builder is a developer tool. It is not meant to be used with user input.
However, the ability to inject CSP directives or additional headers violates the principle of least astonishment.
This was reported via user demonia on HackerOne.
Add support for "unsafe-hashes" directive
Fixed #23 -- duplicate directives are now prevented
Consistently invalidate the compiled CSP cache.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →