NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Packagist · #1294 most downloaded on Packagist
anti xss-library
Last release 2 months ago
10 Jul 2026
Ships unpredictably
gaps range from 9 days to 2.8 years
Most releases are documented
notes for 52 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
12 years old
107 releases · first in 2015
[*]: update the changelog
[*]: update the changelog
One column per quarter.
[+]: optimize performance
[+]: optimize performance
add more js events e.g. "onbeforetoggle"
[*]: update the changelog
[*]: update the changelog
[+]: fix false positive on self-close tags (issue #111 )
[+]: fix false positive on self-close tags (issue #111)
[*]: update the changelog
[*]: update the changelog
[*]: update the changelog v2
[*]: update the changelog v2
[*]: update the changelog
[*]: update the changelog
[*]: update the changelog
[*]: update the changelog
allow e.g. "< 1 year" (issue 83)
fix "_xss_found" if xss string was found in array value
optimize phpdocs + use phpstan-syntax
optimize performance (thx @staabm)
update vendor lib (Portable UTF-8)
allow to skip some html tags from auto closing (issue #63)
fix allow base64 encoded images in -tags (issue #61)
allow e.g. "< $2.20" (issue #60)
allow base64 encoded images in -tags (issue #59)
- fix false-positive (issue #58)
allow to change the "_never_allowed_str_afterwards" (issue #56)
use some more bad strings from "https://github.com/s0md3v/AwesomeXSS"
optimize internal caching of strings
optimize regex for encoded script-tags (%3C && %3E)
fix additional false positives in string (issue #52)
keep more non XSS content from html input
fix open tags problem e.g. "<img/"
add "removeNeverAllowedRegex()"
fix replacing of "-->" (issue #50)
update vendor lib (Portable UTF-8)
add "removeNeverAllowedOnEventsAfterwards()" && "addNeverAllowedOnEventsAfterwards()"
fix replacing of false-positive xss words e.g. " " (issue #44)
fix replacing of false-positive xss words e.g. " " (issue #44)
fix replacing of false-positive xss words e.g. " " (issue #44)
fix replacing of false-positive xss words e.g. "ANAMNESI E VAL!DEFINITE BREVI ORTO" (issue #43)
- optimize the spacing regex
fix replacing of false-positive xss words e.g. "MONDRAGÓN" (issue #43)
fix replacing of false-positive xss words e.g. "DE VAL HERNANDEZ" (issue #43)
fix replacing of false-positive xss words e.g. "Mondragon" (issue #43)
fix issue with "()" in some html attributes (issue #41)
use new version of "Portable UTF8"
fix return type (?string -> string)
use new version of "Portable UTF8"
"UTF7 repack corrected" | thx @alechner #34
keep the input value (+ encoding), if no xss was detected #32
fix "href is getting stripped" #30
- fix "URL escaping bug" #29
- fix usage of "Portable UTF8"
-> this is a breaking change without API-changes - but the requirement from "Portable UTF8" has been changed (it no longer requires all polyfills from…
update "Portable UTF8" from v4 -> v5
-> this is a breaking change without API-changes - but the requirement from "Portable UTF8" has been changed (it no longer requires all polyfills from Symfony)
add "_evil_html_tags" -> so you can remove / add html-tags
- "php": ">=7.0" * use "strict_types" - simplify a regex
- "php": ">=7.0" * drop support for PHP < 7.0
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →