| Name | Modified | Size | Downloads / Week |
|---|---|---|---|
| Parent folder | |||
| 2.0.0 source code.tar.gz | 2026-09-22 | 28.2 kB | |
| 2.0.0 source code.zip | 2026-09-22 | 38.7 kB | |
| README.md | 2026-09-22 | 2.8 kB | |
| Totals: 3 Items | 69.7 kB | 1 | |
google/recaptcha — 2.0.0
Major release introducing strict PHP 8.4+ typing, immutable (readonly) response and parameter value objects, simplified transport constructors, and full PHP 8.5 compatibility.
Upgrading from
1.x? If you cannot yet adopt the breaking API changes below, remain on the^1.5release line (1.5.2), which preserves full1.4.2public API compatibility alongside recent transport security fixes.
Improvements
- Strict Type Safety: Added
declare(strict_types=1)and native scalar parameter, property, and return type declarations acrossReCaptcha,Response,RequestParameters, andRequestMethod. - Immutable Value Objects (
Response&RequestParameters): ConvertedResponseandRequestParameterstoreadonlyclasses with promoted constructor properties. - Streamlined Transport Constructors: Simplified
CurlPostandSocketPostto accept?string $siteVerifyUrl = nulldirectly without intermediate wrapper objects. - Transport Hardening & Proxy Compatibility: Enforced OpenSSL
verify_peer/verify_peer_nameinPost, added 60-second request timeouts, and enabled HTTP/1.1 response status parsing inSocketPost.
Bug Fixes
- PHP 8.5 Compatibility: Removed deprecated
curl_close()call inCurlPostso no deprecation notices are emitted on PHP 8.5 (#630, [#632]). - Socket Handle Cleanup: Fixed an early-return path in
SocketPost::submit()to ensure the open socket is closed ifstream_set_timeout()fails. - Non-Empty
'0'Handling: FixedReCaptchasecret and response validation so the string'0'is treated as a non-empty input rather than discarded byempty().
Breaking Changes
- Minimum PHP Version (
>=8.4): Requires PHP 8.4 or newer. RequestMethod::submit()Return Type: Custom implementations ofReCaptcha\RequestMethodmust declare the native: stringreturn type:public function submit(RequestParameters $params): string.- Strict Scalar Parameter Types: Public methods such as
ReCaptcha::verify(string $response, ?string $remoteIp = null): Responserequirestringrather thannullfor$response(coalesce nullable framework request inputs via$token ?? ''). readonlyDTOs (Response&RequestParameters): Because PHP forbids non-readonly subclasses ofreadonlyclasses,PHPUnit::createMock(Response::class)cannot be used. In unit tests, instantiatenew Response(true, ...)directly or mock theRequestMethodinterface.- Removed
RequestMethod\Curl&RequestMethod\SocketWrappers: TheCurlandSocketwrapper classes have been removed;new CurlPost($siteVerifyUrl)andnew SocketPost($siteVerifyUrl)now take?string $siteVerifyUrl = nullas their first parameter.
Full Changelog: https://github.com/google/recaptcha/compare/1.5.2...2.0.0