NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Packagist · #182 most downloaded on Packagist
A One Time Password Authentication package, compatible with Google Authenticator.
Last release 1 months ago
15 Aug 2026
Release timing varies
gaps range from 9 days to 2.2 years
Some releases are documented
notes for 20 of 36 stable releases
Nothing withdrawn
no release was ever pulled
12 years old
36 releases · first in 2014
Three separate GitHub Actions were stuck on deprecated Node.js 20 (actions/cache, codecov-action's internal pin, actions/setup-node)
PHP 8.6 (beta) support, Psalm static analysis, and CI/governance modernization.
Added
Changed
Fixed
No behavioral changes to secret generation, HMAC computation, or OTP
verification. See docs/audit/9.x-ci-and-governance/03-src-security-review.md
for the line-by-line review.
continue-on-error) while the toolchain catches uppsalm/plugin-phpunit plugin so PHPUnit's TestCase hierarchy resolves correctlycomposer.json support block (issues/source/docs/security) and expanded keywords (totp, hotp, otp, mfa, rfc4226, rfc6238)~9|~10|~11|~12|~13, PHPStan ^1.0|^2.0getTimestamp()'s division (credit: Michal Špaček, cherry-picked from #232)secrets.CODECOV_TOKEN is unavailable (e.g. on fork pull requests)code-quality job (Prettier/Node.js) that never ran against this PHP-only package.scrutinizer.yml, which pointed at a coverage file no longer produced; Codecov already covers thisdocs/audit/9.x-ci-and-governance/03-src-security-review.md for the line-by-line reviewOne column per quarter.
⚠️ Version 9.0.0 Breaking Change
Version 9.0.0 introduces a breaking change: The default secret key length has been increased from 16 to 32 characters for enhanced security.
generateSecretKey() now generates 32-character secrets by default (previously 16)If you want to keep the previous behavior (16-character secrets):
// Old default behavior (v8.x and below)
$secret = $google2fa->generateSecretKey();
// New way to get 16-character secrets (v9.0+)
$secret = $google2fa->generateSecretKey(16);
If you want to use the new default (32-character secrets):
// This now generates 32-character secrets by default
$secret = $google2fa->generateSecretKey();
Potential Impact Areas
- Database schemas: Check if your google2fa_secret columns can handle 32 characters
- Validation rules: Update any length validations that expect exactly 16 characters
- Tests: Update test assertions expecting 16-character secrets
- UI components: Ensure QR code displays and secret key fields accommodate longer secrets
Important: Existing 16-character secrets remain fully functional. Database updates are only needed if you want to use the new 32-character default behavior.
Why This Change?
While 16-character secrets meet RFC 6238 minimum requirements, 32-character secrets provide significantly better security:
- 16 chars: 80 bits of entropy (adequate but minimal)
- 32 chars: 160 bits of entropy (much stronger against brute force)
This change aligns with modern security best practices for cryptographic applications.generateSecretKey() now generates 32-character secrets by defaultgenerateSecretKey(16)Nothing published for this version
Nothing published for this version
### Added - Test using GitHub Actions ### Fixed - Improve PHP 8.1 compatibility
Merge pull request #153 from antonioribeiro/analysis-YjDN3K
Merge pull request #153 from antonioribeiro/analysis-YjDN3K
Apply fixes from StyleCI
[ci skip] [skip ci]
Constants::ARGUMENT_NOT_SET - This is a BC break
### Drafted - To fix inserted BC break
Nothing published for this version
Nothing published for this version
Base exception class and interfaces
### Changed - Remove dead Google Charts API
Nothing published for this version
Nothing published for this version
### Changed - Bacon QRCode package removed
Nothing published for this version
Nothing published for this version
### Changed - Relicensed to MIT
It's now mandatory to enable Google Api secret key access by executing setAllowInsecureCallToGoogleApis(true);
setAllowInsecureCallToGoogleApis(true);Nothing published for this version
Nothing published for this version
Nothing published for this version
Fix Base32 to keep supporting PHP 5.4 && 5.5.
Nothing published for this version
Nothing published for this version
### Fixed - Minor bugs
Drop the Laravel support in favor of a bridge package (https://github.com/antonioribeiro/google2fa-laravel).
Drop support for PHP 5.3.7, require PHP 5.4+.
Package bacon/bacon-qr-code was moved to "suggest".
Allow paragonie/random_compat ~1.4|~2.0.
Bumped christian-riesen/base32 to ~1.3
Nothing published for this version
Fixed URL generation for QRCodes
Nothing published for this version
Nothing published for this version
### Added - First version.
Your coding agent can read these notes before it upgrades. Set up the MCP server →