Download Latest Version 2.1.0 source code.zip (22.2 kB) Google Add to Preferred Sources
Home / 2.0.0
Name Modified Size InfoDownloads / Week
Parent folder
2.0.0 source code.tar.gz 2026-09-22 28.2 kB
2.0.0 source code.zip 2026-09-22 38.7 kB
README.md 2026-09-22 2.8 kB
Totals: 3 Items   69.7 kB 1

google/recaptcha — 2.0.0

Major release introducing strict PHP 8.4+ typing, immutable (readonly) response and parameter value objects, simplified transport constructors, and full PHP 8.5 compatibility.

Upgrading from 1.x? If you cannot yet adopt the breaking API changes below, remain on the ^1.5 release line (1.5.2), which preserves full 1.4.2 public API compatibility alongside recent transport security fixes.

Improvements

  • Strict Type Safety: Added declare(strict_types=1) and native scalar parameter, property, and return type declarations across ReCaptcha, Response, RequestParameters, and RequestMethod.
  • Immutable Value Objects (Response & RequestParameters): Converted Response and RequestParameters to readonly classes with promoted constructor properties.
  • Streamlined Transport Constructors: Simplified CurlPost and SocketPost to accept ?string $siteVerifyUrl = null directly without intermediate wrapper objects.
  • Transport Hardening & Proxy Compatibility: Enforced OpenSSL verify_peer / verify_peer_name in Post, added 60-second request timeouts, and enabled HTTP/1.1 response status parsing in SocketPost.

Bug Fixes

  • PHP 8.5 Compatibility: Removed deprecated curl_close() call in CurlPost so no deprecation notices are emitted on PHP 8.5 (#630, [#632]).
  • Socket Handle Cleanup: Fixed an early-return path in SocketPost::submit() to ensure the open socket is closed if stream_set_timeout() fails.
  • Non-Empty '0' Handling: Fixed ReCaptcha secret and response validation so the string '0' is treated as a non-empty input rather than discarded by empty().

Breaking Changes

  • Minimum PHP Version (>=8.4): Requires PHP 8.4 or newer.
  • RequestMethod::submit() Return Type: Custom implementations of ReCaptcha\RequestMethod must declare the native : string return type: public function submit(RequestParameters $params): string.
  • Strict Scalar Parameter Types: Public methods such as ReCaptcha::verify(string $response, ?string $remoteIp = null): Response require string rather than null for $response (coalesce nullable framework request inputs via $token ?? '').
  • readonly DTOs (Response & RequestParameters): Because PHP forbids non-readonly subclasses of readonly classes, PHPUnit::createMock(Response::class) cannot be used. In unit tests, instantiate new Response(true, ...) directly or mock the RequestMethod interface.
  • Removed RequestMethod\Curl & RequestMethod\Socket Wrappers: The Curl and Socket wrapper classes have been removed; new CurlPost($siteVerifyUrl) and new SocketPost($siteVerifyUrl) now take ?string $siteVerifyUrl = null as their first parameter.

Full Changelog: https://github.com/google/recaptcha/compare/1.5.2...2.0.0

Source: README.md, updated 2026-09-22