NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Packagist · #2858 most downloaded on Packagist
Common utilities and building-blocks for Verbb plugins for Craft CMS.
Last release 3 days ago
04 Oct 2026
Ships unpredictably
gaps range from 8 days to 11 months
Nearly every release is documented
notes for 42 of 42 stable releases
Nothing withdrawn
no release was ever pulled
7 years old
48 releases · first in 2020
One column per quarter.
Fix the shared control-panel layout registering the deprecated asset bundle.
Deprecate the legacy verbb\base\assetbundles\CpAsset and verbb\base\twigextensions\Extension classes in favour of their new web namespace equivalents.
web namespace, and replace CodeKit with Vite for asset builds.verbb\base\assetbundles\CpAsset and verbb\base\twigextensions\Extension classes in favour of their new web namespace equivalents.Bind shared settings saves to the controller’s plugin instead of a request-provided plugin handle.
Fix a SQL injection vulnerability in sandboxed templates.
renderTokens() for non-Twig token replacement using arrays and Yii Arrayable data.renderSandboxedString(), renderSandboxedObjectTemplate() and renderSandboxedTemplate() methods using Base's always-on sandbox, with rendering errors passed to callers.sandboxedAutoescape configuration and per-call autoescape overrides for the explicit renderer.proxyField() and report unsupported field types.is defined checks in sandboxed templates on earlier Craft 5/Twig versions.{site.handle}-style shorthand in sandboxed array-backed object templates.count() in the legacy sandbox renderer as well.null.renderObjectTemplate() and renderString() in favor of their explicitly sandboxed equivalents. The existing methods retain their configuration behavior and logged, empty-string failures.Allow safe model and element properties in sandboxed templates.
Fix a Twig sandbox escape where Illuminate Collection / Enumerable methods such as map , each , and filter accepted PHP string callables (arbitrary fu
Collection/Enumerable methods such as map, each, and filter accepted PHP string callables (arbitrary function invocation).collect from the default sandboxed Twig function allow-list, and stop allowing unrestricted methods on broad Illuminate Enumerable by class family.ElementCollection allowed for legitimate [0] / count access, while denying callable-accepting collection methods (map, each, filter, first, …).AllowableInSandbox deny-by-default for Element objects instead of falling through to a blanket class-family method allow (still permitting __toString for printing elements).Component behaviour APIs (attachBehavior, etc.) on class-family-allowed objects.Twig sandbox now allows methods/properties on safe Craft value objects by class family ( ElementInterface , ElementQueryInterface , ElementCollection
ElementInterface, ElementQueryInterface, ElementCollection, DateTimeInterface, Illuminate Enumerable), instead of requiring plugins to whitelist every method name.allowedClasses support to SecurityPolicy / Templates (merged with the defaults above).#[AllowedInSandbox] attributes when present.{{ fieldHandle.one().title }}) being blocked after the 3.0.10 allow-list enforcement.Fixed object templates escaping HTML variables, outputting them as plain text. Craft 5.10.13 no longer normalises shorthand tags ( {someVar} ) with th
{someVar}) with the raw filter, relying on the escaper strategy being disabled while rendering instead.renderString() with Craft’s default of not auto-escaping HTML (optional $escapeHtml flag to opt in).Respect Craft Monolog target config for Verbb plugin logs.
Allow safe model and element properties in sandboxed templates.
Enforce Twig sandbox method/property allow-lists in SecurityPolicy.
Add CachedElementQuery class for some plugins and element query caching.
CachedElementQuery class for some plugins and element query caching.Add plugin settings and general layouts for easier consistency in plugins.
### Fixed - Fix an error on Craft 5.7+.
Fix an error when calling self::$plugin for modules or plugins that don’t define this property.
self::$plugin for modules or plugins that don’t define this property.Fix an incompatibility with Craft 5.5.0+.
Add proxyField macro to simplify translating field instructions with variables.
proxyField macro to simplify translating field instructions with variables.Allow more Twig functions/filters.
Add support for Closure module and add collect to allowed Twig functions.
collect to allowed Twig functions.Add GlobalsExtension and StringLoaderExtension to template parser.
GlobalsExtension and StringLoaderExtension to template parser.Add support for Craft and plugin Twig extensions in allowed Twig.
ArrayHelper::filterNullFalse().8.2.0+.5.0.0+.Nothing published for this version
Nothing published for this version
Nothing published for this version
Fix a SQL injection vulnerability in sandboxed templates.
renderTokens() for non-Twig token replacement using arrays and Yii Arrayable data.renderSandboxedString(), renderSandboxedObjectTemplate() and renderSandboxedTemplate() methods using Base's always-on sandbox, with rendering errors passed to callers.sandboxedAutoescape configuration and per-call autoescape overrides for the explicit renderer.proxyField() and report unsupported field types.count() in the legacy sandbox renderer as well.null.renderObjectTemplate() and renderString() in favor of their explicitly sandboxed equivalents. The existing methods retain their configuration behavior and logged, empty-string failures.Fix a Twig sandbox escape where Illuminate Collection / Enumerable methods such as map , each , and filter accepted PHP string callables (arbitrary fu
Collection/Enumerable methods such as map, each, and filter accepted PHP string callables (arbitrary function invocation).collect from the default sandboxed Twig function allow-list, and stop allowing unrestricted methods on broad Illuminate Enumerable by class family.ElementCollection allowed for legitimate [0] / count access, while denying callable-accepting collection methods (map, each, filter, first, …).AllowableInSandbox deny-by-default for Element objects (when present) instead of falling through to a blanket class-family method allow (still permitting __toString for printing elements).Component behaviour APIs (attachBehavior, etc.) on class-family-allowed objects.Twig sandbox now allows methods/properties on safe Craft value objects by class family ( ElementInterface , ElementQueryInterface , ElementCollection
ElementInterface, ElementQueryInterface, ElementCollection when available, DateTimeInterface, Illuminate Enumerable), instead of requiring plugins to whitelist every method name.allowedClasses support to SecurityPolicy / Templates (merged with the defaults above).#[AllowedInSandbox] attributes when present (Craft 4.17+).{{ fieldHandle.one().title }}) being blocked after the 2.0.11 allow-list enforcement.Allow safe model and element properties in sandboxed templates.
Enforce Twig sandbox method/property allow-lists in SecurityPolicy.
Fix an incompatibility with Craft 4.13.0+.
Add proxyField macro to simplify translating field instructions with variables.
proxyField macro to simplify translating field instructions with variables.Allow more Twig functions/filters.
Add support for Closure module and add collect to allowed Twig functions.
collect to allowed Twig functions.Add GlobalsExtension and StringLoaderExtension to template parser.
GlobalsExtension and StringLoaderExtension to template parser.Add support for Craft and plugin Twig extensions in allowed Twig.
Add Templates service for easy cut-down, safe Twig string rendering.
Add ability to set Monolog target options.
Add vuiGetValue() as a Twig function for ArrayHelper::getValue().
vuiGetValue() as a Twig function for ArrayHelper::getValue().Fix an error by checking if a dispatcher actually exists before setting its targets. (thanks @boboldehampsink).
### Changed - Switch to Monolog for logging. - Craft 4 upgrade. ### Fixed - Fix credits css.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Fix sidebar tabs not working in some instances, and make fully accessible.
Fix file logging initializing too early before Craft has been bootstrapped.
### Added - Add file logging helper.
### Changed - Lower Craft requirement.
### Changed - Craft 3 upgrade.
Your coding agent can read these notes before it upgrades. Set up the MCP server →