Updated the required version of verbb/base to 3.0.19.
Replaced the CodeKit asset build with Vite and moved web assets and the Twig extension to src/web.
Doxter now purifies Markdown and typography HTML by default. Sites that intentionally render developer-controlled raw HTML must enable allowUnsafeHtml or add narrow purifierConfig allowances.
Improved Doxter field performance by parsing Markdown only when rendered and caching repeated output.
Improved typography rendering performance by reusing the parser's internal caches.
Fixed
Fixed a moderate-severity stored XSS vulnerability.
Fixed a low-severity stored XSS vulnerability.
Fixed a low-severity denial-of-service vulnerability.
Fixed a low-severity path traversal vulnerability.
Fixed a low-severity information disclosure vulnerability.
Fixed an error when parsing Markdown files with front matter.
Fixed programmatically registered shortcodes not invoking their callbacks.
Fixed shortcode stripping not recognizing configured template tags.
Fixed before-parse event changes not being applied to subsequent parsing stages.
Fixed table-of-contents links not matching rendered heading anchors.
Fixed bundled shortcode paths and documentation to match site template resolution.
Fixed PHP 8.4 deprecations and errors when normalising non-string field values.
Fixed bundled shortcode templates using unscoped parameters and arbitrary image wrapper tags.
Fixed the field editor loading icon and spell-check resources from third-party CDNs.
6.0.5 2026-09-30
Changed
Route plugin settings through the plugin’s authorized settings controller.
6.0.4 2026-09-14
Changed
Updated documentation for clearer, more consistent guidance.
Clarified optional PHP configuration with focused examples and linkable setting details.
6.0.3 2026-09-13
Changed
Normalize plugin settings.
6.0.2 2026-05-10
Fixed
Fix disabling spellcheck so it also disables native browser spellcheck in the editor.