NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Packagist · #463 most downloaded on Packagist
A PHP library for XML Security
Last release 1 months ago
22 Aug 2026
Ships unpredictably
gaps range from 2 weeks to 4.2 years
Some releases are documented
notes for 6 of 23 stable releases
Nothing withdrawn
no release was ever pulled
11 years old
25 releases · first in 2015
DOCTYPE rejected on signature verify (entity-ref / Id bypass; same class of issue as CVE-2025-23369 ); also rejected in decrypted XML
PHP 8.0+ and phpseclib/phpseclib ~3.0 required; OpenSSL is optional.
RSA_SHA256_MGF1) supportedverifyDocument() — pinned key, algorithm allowlists, validated node setenableLegacyMode() for temporary pre-4.0 interop while migrating peersstripWhitespace; omit_uri for references without a URI; extensibility via protected members (#152)verify() always binds SignatureMethod to the supplied key; HMAC cannot be loaded from certs/PEMadd509Cert() URL fetch; EncryptedKey/RetrievalMethod depth caps; hash_equals for digests/HMACsetSignatureId(); clearer throws when signature context is missingmakeAsnSegment()Prefer verifyDocument() with a pinned key. Use enableLegacyMode() only while updating peers — it restores DOCTYPE-on-verify, XPath transforms, and RSA-1.5; it does not undo algorithm/key binding, uniform decrypt errors, or decrypted-XML DOCTYPE rejection. Prefer RSA-OAEP and AES-GCM for new deployments.
Full detail: CHANGELOG.txt (4.0.0) and the “Breaking changes (3.1 → 4.0)” section in README.md.
Full Changelog: 3.1.5...4.0.0
One column per quarter.
Nothing published for this version
Nothing published for this version
Validate AES-GCM Authentication Tag
Validate AES-GCM Authentication Tag
fix canonicalization error
fix canonicalization error
Removes BC breaking change
Removes BC breaking change
Add tab to list of whitespace values to remove from cert loadKey should check return value for openssl_get_privatekey Switch to GitHub actions Support
Add tab to list of whitespace values to remove from cert
loadKey should check return value for openssl_get_privatekey
Switch to GitHub actions
Support OAEP (from unreleased 3.1.1)
Nothing published for this version
Add support for AES-GCM encryption Minor improvements and bug fixes
Add support for AES-GCM encryption
Minor improvements and bug fixes
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →