NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Packagist · #344 most downloaded on Packagist
Pure PHP implementation of libsodium; uses the PHP extension if it exists
Last release 1 months ago
18 Aug 2026
Release timing varies
gaps range from 9 days to 13 months
Rarely documented
notes for 10 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
10 years old
85 releases · first in 2017
Fix cryptographic boundary and validation failures by @paragonie-security in #208
Full Changelog: v2.5.1...v2.5.2
Fix Ed25519 main subgroup validation by @paragonie-security in #206
Full Changelog: v2.5.0...v2.5.1
One column per quarter.
Read: A vulnerability in libsodium
Read: A vulnerability in libsodium
This fixes a congruent issue in the main branch of the PHP implementation.
For older PHP versions, see v1.24.0 instead.
The biggest change (besides unit testing) in this release is the optimization of Curve25519 field arithmetic by using object properties instead of an
The biggest change (besides unit testing) in this release is the optimization of Curve25519 field arithmetic by using object properties instead of an internal array. This skips some internal overhead in PHP (i.e., hash tables and memory allocation) that we ultimately never needed.
Beyond that, we mostly expanded our unit test coverage. We're running Infection to identify code that can be mutated without the test suite failing, and it's identified a lot of false positives but also some useful information. The end result? We've fixed a few bugs.
Util::(strlen|substr) by @takaram in #201Full Changelog: v2.3.1...v2.4.0
Deletes the erroneous PSR-0 autoloader declaration from composer.json, fixing #196
Deletes the erroneous PSR-0 autoloader declaration from composer.json, fixing #196
Full Changelog: v2.3.0...v2.3.1
Important The previous version of sodium_compat was overly permissible with sodium_base642bin() when the *_NO_PADDING variants were specified, which w
Important
The previous version of sodium_compat was overly permissible with sodium_base642bin() when the *_NO_PADDING variants were specified, which was not compatible with ext-sodium. This has been fixed in v2.3.0.
If you need the old behavior in the meantime, you can call ParagonIE_Core_Base64_Original::decode() or ParagonIE_Core_Base64_UrlSafe:decode() to get lax padding enabled.
Aside from this fix, most of the changes were to the unit test suite in order to improve our mutation testing metrics.
Full Changelog: v2.2.0...v2.3.0
Nothing published for this version
Nothing published for this version
Nothing published for this version
Backport cryptographic boundary and validation fixes by @paragonie-security in #209
Full Changelog: v1.24.1...v1.24.2
Fix Ed25519 main subgroup validation by @paragonie-security in #207
Full Changelog: v1.24.0...v1.24.1
Read: A vulnerability in libsodium
Read: A vulnerability in libsodium
This fixes a congruent issue in the v1.x branch of the PHP implementation.
We backported some optimizations from #198 by replacing the array in the Curve25519 field element with 10 integer object properties instead. The resul
We backported some optimizations from #198 by replacing the array in the Curve25519 field element with 10 integer object properties instead. The result is a 7% to 12% speedup for the overall PHPUnit suite.
Full Changelog: v1.22.0...v1.23.0
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →