From f014e0d4f0bbf06e456b5f28a55fbac9de1cd951 Mon Sep 17 00:00:00 2001 From: thisismyurl <122108986+thisismyurl@users.noreply.github.com> Date: Tue, 14 Jul 2026 08:58:51 -0400 Subject: [PATCH] Remove deprecated utf8_encode() from the pwned-password check utf8_encode() is deprecated as of PHP 8.2. Here it wraps strtoupper( sha1( $password ) ), which is always a pure-ASCII hex string, so the call is a no-op: utf8_encode() returns that string unchanged. Dropping it removes the deprecation notice with no change to $password_hash or the downstream HIBP range lookup. --- lib/Security.php | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/lib/Security.php b/lib/Security.php index 50580785..842efe92 100644 --- a/lib/Security.php +++ b/lib/Security.php @@ -38,7 +38,7 @@ public function hooks() : void { * @return bool */ public static function check_password_pwnd_status( string $password ) { - $password_hash = utf8_encode( strtoupper( sha1( $password ) ) ); + $password_hash = strtoupper( sha1( $password ) ); $k_anon = substr( $password_hash, 0, 5 ); $service_url = 'https://api.pwnedpasswords.com/range/' . $k_anon;