NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Packagist · #3983 most downloaded on Packagist
Slim Framework 4 CSRF protection PSR-15 middleware
Last release 11 months ago
02 Nov 2025
Release timing varies
gaps range from 1 weeks to 1.8 years
Some releases are documented
notes for 12 of 22 stable releases
Nothing withdrawn
no release was ever pulled
12 years old
22 releases · first in 2015
Support PHP 8.4 & 8.5 by @akrabat in #195
Bump psr/http-message requirement from '^1.0' to '^1.0 || ^2.0' by @odan in #184
One column per quarter.
Update phpspec/prophecy requirement from ^1.15 to ^1.16 by @dependabot in #167
Full Changelog: 1.3.0...1.4.0
133: Upgrade to GitHub-native Dependabot thanks to @dependabot-preview [bot]
Total issues resolved: 13
This release makes using an Interator for the backing storage much better.
This release makes using an Interator for the backing storage much better.
Total issues resolved: 3
129: Support PHP 8 and remove 7.1 and 7.2 thanks to @akrabat
Total issues resolved: 1
Note that this release includes a fix for replay attacks when using Slim-Csrf in non-persistent mode. Upgrading to this version is recommended.
Note that this release includes a fix for replay attacks when using Slim-Csrf in non-persistent mode. Upgrading to this version is recommended.
Total issues resolved: 10
remoteTokenFromStorage() is now public105: PSR-15 Support thanks to @l0gicgate
Total issues resolved: 1
87: Widen random_compat constraint to include versions 9.99.X thanks to @ethanbray
Total issues resolved: 1
68: just adding sixth constructor param to phpdoc
Fixed: Default stroageis now $_SESSION again
Added: Now supports "persistence mode", to persist a single CSRF name/value pair throughout the life of a user's session. Added the following methods:
Added: Now supports "persistence mode", to persist a single CSRF name/value pair throughout the life of a user's session. Added the following methods:
protected getLastKeyPair - gets the most recently generated key/value pair from storage.protected loadLastKeyPair - gets the most recently generated key/value pair from storage, and assign it to $this->keyPair.public setPersistentTokenModepublic getPersistentTokenModeNote that if CSRF token validation fails, then the token should be renewed regardless of the persistence setting.
The methods getTokenName and getTokenValue now return null if $this->keyPair has not yet been set.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →