| Name | Modified | Size | Downloads / Week |
|---|---|---|---|
| Parent folder | |||
| 1.10.5 source code.tar.gz | 2026-08-24 | 5.7 MB | |
| 1.10.5 source code.zip | 2026-08-24 | 5.8 MB | |
| README.md | 2026-08-24 | 2.0 kB | |
| Totals: 3 Items | 11.5 MB | 0 | |
YOURLS 1.10.5 (announcement)
What's Changed
- fixed and improved: numerous misc. security hardening
- We have phased out
md5in Passwordless API and credentials, without breaking existing installs - We're making extensive use of
hash_equals()to beat time based attacks - Cookie prefixes are implemented for browser-side hardening on HTTPS installs
YOURLS_COOKIEKEYis now unpredictable when not user defined- Remote title fetching is now restricted on a public install when shortening private IP
- We have enhanced the Pages feature to prevent an unauthenticated file inclusion under very unlikely conditions
- Support for proxies and specifically trusted proxies has been improved See [#4111], [#4122], [#4119], [#4139], [#4141], [#4145], [#4147], [#4142].
- improved: unit tests, to handle more scenarios and make tests independent of constants, to eventually deprecate some constants (#4124)
- changed: Return
HTTP 409 Conflict(not400) when a duplicate long URL is rejected, by @TowyTowy [#4133]
Full Changelog: https://github.com/YOURLS/YOURLS/compare/1.10.4...1.10.5
How to install or update
Download the source code below and upload it to your server. We recommend backing up your DB before any update.
More detailed instructions are available on https://yourls.org/docs/
Shorten your links and make YOURLS bigger!
Does your company use YOURLS? Help the project, become a sponsor, and get your logo on our README on GitHub with a link to your site. Become a sponsor.
New Contributors
- @TowyTowy made their first contribution in https://github.com/YOURLS/YOURLS/pull/4133
Full Changelog: https://github.com/YOURLS/YOURLS/compare/1.10.4...1.10.5