Healthy and suitable to depend on. It has a long, active release history, recent work from five contributors, and strong repository and licensing transparency; review the repository’s GitHub Actions permissions before adopting it in a sensitive build environment.
93%
Total Score
100
50
100
70
One of five workflows uses pull_request_target, which warrants review because that trigger can handle untrusted pull-request input with elevated repository context; no untrusted checkouts or script injection were detected.
The package has 16 runtime dependencies, including framework components and image or filesystem support libraries; this is a meaningful dependency surface but is consistent with its broad media-handling functionality.
The repository has no published security policy, leaving vulnerability-reporting and response expectations less transparent than ideal for a widely used package.
Four workflows lack top-level token permissions, and one workflow has top-level write access. This is a permissions-hygiene gap, although no broader workflow execution flaws were found.
| Title | Versions | Severity |
|---|---|---|
CVE-2026-48555 spatie/laravel-medialibrary is vulnerable to Server-Side Request Forgery (SSRF) in versions 0.0.0 - 11.23.0. | 0.0.0 - 11.23.0 | High |
CVE-2026-48557 spatie/laravel-medialibrary is vulnerable to Incomplete List of Disallowed Inputs in versions 0.0.0 - 11.23.0. | 0.0.0 - 11.23.0 | High |
AIKIDO-2024-10189 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. spatie/laravel-medialibrary is vulnerable to Unrestricted Upload of File with Dangerous Type in versions 8.0.0 - 11.7.3. | 8.0.0 - 11.7.3 | High |
| Dependency | Last Release | Score |
|---|---|---|
spatie/image Version ^3.3.2 | — | — |
illuminate/bus Version ^10.2|^11.0|^12.0|^13.0 | — | — |
composer/semver Version ^3.4 | — | — |
symfony/console Version ^6.4.1|^7.0|^8.0 | — | — |
illuminate/console Version ^10.2|^11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.