Healthy and suitable to depend on, with a maintenance caveat. It has a long release history, a current stable release, organization backing, tests, and security documentation, but recent repository activity is very thin and concentrated in one contributor.
78%
Total Score
63
100
94
100
All recent commit activity came from one contributor, creating concentration risk; organization ownership provides some handoff capacity but does not remove the thin recent activity signal.
Only 1 commit was made in the last 3 months by 1 active maintainer, indicating very limited recent development even though the registry released a version during the period.
There are 214 open issues, while the last month shows 1 new issue, no closed issues, and no merged pull requests; the unresolved backlog is a maintenance caution despite low recent incoming activity.
The repository uses Make and Composer, but no security scanning tools were detected; the build tooling is positive while the absent scanning is a modest transparency gap.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2024-10395 unisharp/laravel-filemanager is vulnerable to Unrestricted Upload of File with Dangerous Type in versions 1.0.0 - 2.9.0. | 1.0.0 - 2.9.0 | High |
CVE-2022-40734 unisharp/laravel-filemanager is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in versions 0.0.0 - 2.6.4. | 0.0.0 - 2.6.4 | Medium |
CVE-2021-23814 unisharp/laravel-filemanager is vulnerable to Unrestricted Upload of File with Dangerous Type in versions 0.0.0 - 2.6.2. | 0.0.0 - 2.6.2 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
composer/semver Version ^3.4 | — | — |
illuminate/http Version ^6.0 || ^7.0 || ^8.0 || ^9.0 || ^10.0 || ^11.0 || ^12.0 || ^13.0 | — | — |
league/flysystem Version >=2.0.0 | — | — |
illuminate/config Version ^6.0 || ^7.0 || ^8.0 || ^9.0 || ^10.0 || ^11.0 || ^12.0 || ^13.0 | — | — |
illuminate/support Version ^6.0 || ^7.0 || ^8.0 || ^9.0 || ^10.0 || ^11.0 || ^12.0 || ^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.