Skip to main content
Redian Software
Engineering 21 Nov 2016

CodeIgniter 3.1.0 Released with security fixes, bug fixes and enhancements

CodeIgniter 3.1.0 was released, with some security fixes, bug fixes & enhancements. Most importantly, it fixes a critical SQL injection bug in the ODBC database driver, now no longer use the query builder with it, nor the escape functions &

R

Redian Software

Share
CodeIgniter 3.1.0 Released with security fixes, bug fixes and enhancements
Featured image · Redian Software editorial

CodeIgniter 3.1.0 was released with a useful bundle of security fixes, bug fixes and enhancements. For teams maintaining PHP applications in production, this was one of the more consequential point releases in the 3.x line, because it tightened a database driver that had been quietly exposing real risk.

The ODBC security fix

Most importantly, this release fixes a critical SQL injection bug in the ODBC database driver. The fix is not a small one: the changes to the ODBC driver mean that you can no longer use the query builder with it, nor the escape() functions. On the plus side, the driver now has actual query binding rather than the emulated binding that previous versions relied on. True binding is the right long-term answer — it pushes parameter handling down to the database layer where it belongs, rather than trying to sanitise SQL strings in PHP.

The ODBC fixes are not backwards compatible, which is why the version number bumps from 3.0.x to 3.1.0. The team also raised the minimum PHP version to 5.3.7. Any previous in-progress changes that had been targeted for 3.1.0 are now retargeted for 3.2.0.

What else got fixed and improved

Beyond ODBC, this release includes bug fixes across a wide surface area of the framework: the Cache, Config, Database, Database Forge, Email, File Uploading, Form Validation, Image Manipulation, Input Library, Query Builder, Session, and User Agent libraries, along with the file and path helpers and some common functions. Enhancements were also rolled into the Database Forge, Encryption, Image Manipulation and Session libraries — the parts of the framework most directly exposed to user input and persistence.

Why it still matters

CodeIgniter is no longer the headline PHP framework it once was, but it still runs a long tail of business applications — admin panels, integration middleware, legacy customer portals — quietly delivering value years after launch. If you are auditing one of those systems today, 3.1.0 is the minimum baseline you want for any ODBC-backed deployment. Anything older should be patched or migrated.

For teams looking at a more strategic move — replatforming a custom PHP CRM onto Zoho(/expertise/crm/zoho), SuiteCRM(/expertise/crm/suitecrm), or Odoo(/expertise/crm/odoo) — the security audit of an old CodeIgniter app is often where the business case begins. Our CRM and ERP implementation team(/services/crm-erp-implementation) has walked clients through exactly that migration path, and the case studies are collected in our client work(/case-studies).

Stay current with our insights

One monthly email. Banking, insurance, AI/ML and CRM field notes. No spam.

We respect your privacy. Read our Privacy Policy.

Build with Redian

Have a similar build in mind?

We've shipped engineering systems for banks, insurers, brokers, MFIs, SACCOs and enterprises across the USA, UK, Africa, UAE and India. Book a 30-min call with a senior engineer — no pitch deck, just a sharp first read on your initiative.

  • CMMI Level 3 Appraised · ISO Certified delivery
  • 1 business day response · NDA on request
  • Senior engineers, not sales — first call