Download the PHP package bariew/whatsapp-crypto without Composer
On this page you can find all versions of the php package bariew/whatsapp-crypto. It is possible to download/install these versions without Composer. Possible dependencies are resolved automatically.
Download bariew/whatsapp-crypto
More information about bariew/whatsapp-crypto
Files in bariew/whatsapp-crypto
Package whatsapp-crypto
Short Description PSR-7 stream decorators for WhatsApp-style encryption and decryption
License MIT
Informations about the package whatsapp-crypto
WhatsApp Crypto
PSR-7 stream decorators for WhatsApp-style encryption and decryption of media files. This library implements the same encryption algorithm used by WhatsApp to encrypt images, videos, audio, and documents.
Features
- Stream-based encryption/decryption: Uses PSR-7 stream decorators for memory-efficient processing
- WhatsApp-compatible: Implements the exact same encryption algorithm as WhatsApp
- Chunk-based MAC generation: Supports sidecar file generation for streaming scenarios
- No external dependencies: Only requires PHP extensions that are commonly available
- Well-tested: Comprehensive unit and integration tests with sample files
Installation
Install the package via Composer:
Requirements
- PHP 7.4 or higher
ext-opensslextensionext-hashextensionpsr/http-message(^1.0 or ^2.0)guzzlehttp/psr7(^2.0)
Quick Start
Encrypting a File
Decrypting a File
Testing
Run the test suite:
The project includes integration tests with sample files for AUDIO, IMAGE, and VIDEO media types.
Sample Files
The samples/ directory contains test files:
*.original- Original unencrypted files*.encrypted- Encrypted versions using WhatsApp-compatible encryption*.key- The 32-byte mediaKeys used for encryptionVIDEO.sidecar- Example sidecar file for chunk-based verification
Security Considerations
- MAC Truncation: WhatsApp uses the first 10 bytes of HMAC-SHA256. This is a deliberate design choice for compactness, though it reduces the theoretical security margin.
- Timing-Safe Comparison: The library uses
hash_equals()for MAC verification to prevent timing attacks. - Key Management: Keep your mediaKeys secure. Anyone with the mediaKey can decrypt the corresponding media.
License
This package is open-source software licensed under the MIT license.
Credits
This implementation is based on the WhatsApp encryption protocol as documented in various reverse-engineering efforts and the Signal protocol specifications.
All versions of whatsapp-crypto with dependencies
psr/http-message Version ^1.0|^2.0
guzzlehttp/psr7 Version ^2.0
ext-openssl Version *
ext-hash Version *