AES-GCM: the authenticated encryption the real web actually uses
v0.1.92 added AES in the CTR and CBC modes but deliberately left out GCM, because its authentication tag is a separate primitive and shipping it unverified would have been dishonest. That caution is now retired the right way: GCM is implemented in full - the GHASH multiply in GF(2^128), the counter derivation, and the tag - and verified byte-for-byte, TAG INCLUDED, against the canonical GCM test vectors. GCM is the mode the web runs on (it is what TLS, WebCrypto and JSON Web Encryption use), and the difference from CTR/CBC is that it is AUTHENTICATED: decryption recomputes the tag and refuses a tampered message rather than handing back forged plaintext. The Web API figure moves one point for completing the AES mode set with the one that matters most.