Article
Replacing mcrypt_encrypt()
Remove mcrypt_encrypt() safely: lifecycle, modern replacements, and migration examples for legacy PHP apps.
mcrypt_encrypt() encrypted data with algorithms/modes from libmcrypt. Padding behavior and mode defaults differ from modern OpenSSL/libsodium APIs, so ciphertext compatibility must be verified—not assumed.
Lifecycle (php.net)
- Deprecated: ext/mcrypt deprecated as of PHP 7.1.0
- Removed: PHP 7.2.0
Modern replacement
Prefer libsodium (sodium_crypto_secretbox / AEAD) for new data. For historical ciphertext, decrypt with a controlled transitional tool, then re-encrypt. OpenSSL equivalents require explicit attention to key length, IV, and PKCS#7 padding.
Migration example
# LEGACY — mcrypt_encrypt()
$cipher = mcrypt_encrypt(MCRYPT_RIJNDAEL_128, $key, $plain, MCRYPT_MODE_CBC, $iv);
# MODERN
$nonce = random_bytes(SODIUM_CRYPTO_SECRETBOX_NONCEBYTES);
$cipher = sodium_crypto_secretbox($plain, $nonce, $key);
# store $nonce alongside ciphertext
Security note: treat key handling and IV/nonce uniqueness as part of the migration design review—not an afterthought.
Scan before cutover
Search the tree for mcrypt_encrypt() and paste samples into the PHP Version Compatibility Checker and PHP Deprecated Checker.
Related tools
- Composer.json Validator Validate composer.json structure and common mistakes without running composer install.
- Legacy PHP Risk Checker Paste PHP source for a static scan that classifies removed APIs, deprecated calls, and security-sensitive leg…
- PHP Deprecated Checker Find deprecated functions and patterns in pasted PHP to prioritize modernization work.
- PHP Environment Compare Compare two PHP environment summaries to find directive and extension mismatches.
- PHP Modernization Roadmap Build an ordered migration stage list from your PHP version, framework, Composer, database API, and deploymen…
- PHP Version Compatibility Checker Scan pasted PHP for version-sensitive syntax and APIs to plan upgrades across PHP releases.
Related reading
- Composer Modernization Center Add Composer to legacy PHP projects, migrate includes to autoloading, set platform constraints, and replace a…
- PHP 5 to Modern PHP: Complete Incremental Migration Guide A deep, production-minded path from PHP 5.x codebases to supported PHP 8.x: removed extensions, charset, PDO,…
- PHP Security Modernization for Legacy Applications Upgrade inherited PHP security practices: prepared statements, password hashing, sessions, CSRF, XSS escaping…
- PHP 7 to PHP 8 Migration Guide Deep guide to PHP 8.0 breaking changes that matter for PHP 7 applications, with upgrade tactics through suppo…
- Inheriting a Legacy PHP Application A first-30-days playbook for developers handed an unfamiliar PHP codebase: runtime truth, risk triage, and sa…