NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Packagist · #395 most downloaded on Packagist
Deprecated legacy PDF engine for PHP. Use instead tecnickcom/tc-lib-pdf.
Last release 4 days ago
03 Oct 2026
Release timing varies
gaps range from 9 days to 6 months
Most releases are documented
notes for 50 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
13 years old
160 releases · first in 2013
Full Changelog : 7.0.13...7.0.15
Full Changelog: 7.0.13...7.0.15
Composer\InstalledVersions is loaded before TCPDF: the install path may contain '..' segments (e.g. 'vendor/composer/../'), which the file helper rejects. The detected font directory is now resolved with realpath().tecnickcom/tc-lib-pdf ^8.78.One column per quarter.
Full Changelog : 7.0.12...7.0.13
Full Changelog: 7.0.12...7.0.13
tecnickcom/tc-lib-pdf ^8.77.Full Changelog : 7.0.11...7.0.12
Full Changelog: 7.0.11...7.0.12
Full Changelog : 7.0.10...7.0.11
Full Changelog: 7.0.10...7.0.11
Full Changelog : 7.0.9...7.0.10
Full Changelog: 7.0.9...7.0.10
Output::savePDF(), which takes a directory. The path is now split into the directory and the file name.
- The file name is sanitized by the engine, so the file written may differ from the name given ('my_report.final.pdf' is written as 'my_report_final.pdf'). Use TCPDF::getPDFFilename() for the effective name.
- The output directory is subject to the same allowlist as local reads: directories outside the built-in defaults (system temp dir, K_PATH_MAIN, the working directory, K_PATH_FONTS, K_PATH_IMAGES, the script directory) must be added to K_ALLOWED_PATHS before tcpdf.php is loaded. Failures now report that instead of 'invalid file'.
Output($name, false) previously streamed the document to the browser instead of saving it.tecnickcom/tc-lib-pdf ^8.75.Full Changelog : 7.0.8...7.0.9
Full Changelog: 7.0.8...7.0.9
Full Changelog : 7.0.7...7.0.8
Full Changelog: 7.0.7...7.0.8
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
TCPDF IS DEPRECATED AND IN MAINTENANCE-ONLY MODE
tecnickcom/tc-lib-pdf engine. It does not reproduce legacy output exactly, and some methods are adapters, shims, or no-ops (see MAPPING.md); both new and existing projects are encouraged to migrate to tecnickcom/tc-lib-pdf.
TCPDF class no longer contains its own PDF engine; every public method delegates rendering to \Com\Tecnick\Pdf\Tcpdf, while a small internal state layer reproduces the legacy cursor/page model (X/Y, margins, fonts, colors, automatic page breaks, headers/footers).delegated, adapter, shim, intentional-noop, blocked), machine-verified against the class.tecnickcom/tc-lib-pdf is now a required Composer dependency; the engine and font assets are resolved from vendor/.include/, tcpdf_fonts.php, tcpdf_font_data.php, tcpdf_images.php, tcpdf_static.php, tcpdf_barcodes_1d.php, tcpdf_barcodes_2d.php); these capabilities are now provided by the tc-lib-* libraries.tecnickcom/tc-lib-pdf-font assets resolved via Composer.
vendor/tecnickcom/tc-lib-pdf-font/target/fonts/ exists.fonts/ assets are removed; use tc-lib font assets or explicit custom font paths.fontname.php + fontname.z) are no longer supported; convert the original TTF/OTF with the tc-lib-pdf-font importer.test/, added Mago lint/format configuration, and refreshed CI and Makefile targets (make deps, make fonts, make fonts-rebuild).Nothing published for this version
Added Makefile for common automation tasks.
- Refactor setCompression().
Remove debug line preventing compression.
Fix PHP 8.5 deprecation on curl_close() - PR #838
Fix PHP 8.5 deprecation for xml_parser_free - PR #835
Embedded files support (Factur-X 1.07 / ZUGFeRD 2.3) #789
- Update donation link.
New fix for "Deserialization of untrusted data" (check on valid protocols).
Quick fix for "Deserialization of untrusted data" security vulnerability reported by Positive Technologies.
Fixed "Path Traversal" security vulnerability reported by Positive Technologies.
Removed tcpdf_import.php and tcpdf_parser.php files (for a parser check the tc-lib-pdf-parser project instead).
Fix some annotation flags values.
Requires PHP 7.1+ and curl extension.
Improve SVG detection by checking for (mandatory) namespace.
Update regular expression to avoid ReDoS (CVE-2024-22641)
Forbid access to parent folder in HTML images.
- Update GitHub actions - fix: CSV-2024-22640
[BREAKING CHANGE] The tcpdf HTML tag syntax has changed, see example_049.php.
Avoid a deprecated error from PHP8.1
Add PHPStan and fix level 1 errors
Multi-byte character support for filename during output (#561).
encodeUrlQuery takes into account the port
- PHP 8.1 fixes
Fix type hint for \TCPDF_STATIC::_freadint
Fix PHP 8.1 type error with TCPDF_STATIC::pregSplit on preg_split
Update tcpdf version (no code changes)
Fixed a syntax error issue when accessing an index of a casted variable
- Check if imagekeys exist - Unlink only images in cache
Fixed PHP 7.4 - cannot use array offset on integers
- Update ICC profile
Fix Undefined property: GLPIPDF::$imagekeys
Fix Array and string offset access syntax with curly braces is deprecated
Update sRGB.icc with the one from the Debian package icc-profiles-free
- Fix support for image URLs.
- Simplify file_exists function.
Fixes on include/tcpdf_images.php, include/tcpdf_static.php and tcpdf.php about file handling
include/tcpdf_images.php, include/tcpdf_static.php and tcpdf.php about file handling- _no code changes_
Fix for security vulnerability: Using the phar:// wrapper it was possible to trigger the unserialization of user provided data.
Merge various fixes for PHP 7.3 compatibility and security.
Nothing published for this version
Nothing published for this version
IMPORTANT: A new version of this library is under development at https://github.com/tecnickcom/tc-lib-pdf and as a consequence this version will not r
fix composer package name to tecnickcom/tcpdf
Bug #1070 "PNG regression in 6.2.9 (they appear as their alpha channel)" was fixed.
Your coding agent can read these notes before it upgrades. Set up the MCP server →