Still on Drupal 7? Security support for Drupal 7 ended on 5 January 2025. Please visit our Drupal 7 End of Life resources page to review all of your options.
This release contains an important security fix. Users of the module are strongly encouraged to update to this version as soon as possible.
If you are using an older version, incorrectly escaped error messages might lead to your site being vulnerable to an XSS attack. Note, however, that this can only occur if you somehow allow users to specify the used internal field identifiers (e.g., through Views exposed sorts or the old (deprecated) Search API Facets module).
This release contains only one change compared to the previous Beta 2 release: some error messages weren't properly escaped, which has now been fixed.
Since this might lead to an XSS vulnerability on your site (depending on the rest of your search setup), it is strongly recommended that you update to this new version.
This release contains only one change compared to the previous Beta 2 release: some error messages weren't properly escaped, which has now been fixed.
Since this might lead to an XSS vulnerability on your site (depending on the rest of your search setup), it is strongly recommended that you update to this new version.
This is the fourth alpha release. Major new features are postponed until Payment 7.x-2.x. Only bug fixes and small improvements will continue to be added to 7.x-1.x.