NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Packagist · #3763 most downloaded on Packagist
A package for easily uploading and attaching media files to models with Laravel
Last release 3 days ago
04 Oct 2026
Release timing varies
gaps range from 3 weeks to 12 months
Nearly every release is documented
notes for 55 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
10 years old
96 releases · first in 2016
Disallow .INI, .ACA, .CER files by default
Full Changelog: 7.1.0...7.1.1
Added support for Guzzle 8, along with its guzzlehttp/psr7 3.x and guzzlehttp/promises 3.x dependency stack. Guzzle 7 remains supported.
guzzlehttp/psr7 3.x and guzzlehttp/promises 3.x dependency stack. Guzzle 7 remains supported.mediable.forbidden_file_extensions. All usage is now aligned to use the mediable.forbidden_extensions naming.Full Changelog: 7.0.2...7.1.0
One column per quarter.
Disallow PHT files by default by @m-triassi in #396
Full Changelog: 7.0.1...7.0.2
This is a security release, upgrading is strongly recommended
This is a security release, upgrading is strongly recommended
mediable.validate_remote_url_redirects config to false.mediable.max_remote_url_redirects config, which limits the number of redirects that will be followed when mediable.validate_remote_url_redirects is enabled. If the limit is exceeded, an exception will be thrown.MediaUploader to throw an exception when depending on the configured mediable.default_diskFull Changelog: 7.0.0...7.0.1
This is a security release, upgrading is strongly recommended
This is a security release, upgrading is strongly recommended
mediable.allowed_remote_hosts configuration which allows restricting remote URL source adapters to a whitelist. Wildcard subdomains may be specified with *.example.com syntax. By default, all hosts are allowed.mediable.allowed_remote_hosts allow list is provided, the RemoteUrlAdapter will reject private IP addresses and localhost by default, to prevent Server-Side Request Forgery (SSRF) attacks. [CVE-2026-49969]mediable.allowed_remote_schemes configuration which allows restricting remote URL source adapters to a whitelist of allowed URL schemes (e.g. http, https, ftp, etc.). By default, only https is allowed. When modifying this configuration, it may also be necessary to modify the source_adapters pattern matching.. characters from path segments. This prevents attackers from using directory traversal patterns like ../ as well as preventing potential issues with certain filesystems where . characters in directory names may cause unexpected behaviour. [CVE-2026-49970]mediable.file_sanitizers configuration which allows specifying custom sanitizers for rewriting file contents to strip out security risks before they are uploaded. A sanitizer must implements the Plank\Mediable\Sanitizers\SanitizerInterface interface.SvgSanitizer which will strip executable javascript and other untrusted content from image/svg+xml files, which can result in stored XSS if rendered directly to a webpage. By default, this sanitizer is applied to all uploaded SVG files. It can be disabled by removing it from the mediable.sanitizers config array. [CVE-2026-49971]mediable.forbidden_file_extensions configuration and MediaUploader::setForbiddenExtensions() which allows specifying a blacklist of file extensions that are forbidden to be uploaded. Any file extension which is considered executable by your Apache or Nginx configuration should be included in this list. A number of common executable file extensions are included in this list by default to prevent remote code execution exploits.script.php.jpg becomes script-php.jpg). This prevents remote code execution from double extension bypass due to common Apache and Nginx misconfigurationsmediable.forbidden_mime_types configuration and MediaUploader::setForbiddenMimeTypes() which allows specifying a blacklist of MIME types that are forbidden to be uploaded.Plank\Mediable\Enum\OnDuplicateBehaviour enum.MediaUploaderConfiguration class. Most MediaUploader instance properties are moved to this class. The MediaUploader class now accepts this as a constructor argument instead of an array of configs.MediaUploader::beforeSave() now accepts a \Closure instead of a callable for better static analysis and type safety.Full Changelog: 6.5.0...7.0.0
Deprecated ImageManipulation::setOutputQuality() . Use the 'quality' key in setOutputOptions() instead
ImageManipulation::setOutputOptions(), to support various intervention/image output format settingsImageManipulation::setOutputQuality(). Use the 'quality' key in setOutputOptions() insteadFull Changelog: 6.4.0...6.5.0
Minimum supported PHP version is now 8.3
Full Changelog: 6.3.1...6.4.0
Don't require CLI to execute migrations by @syssi in #376
Full Changelog: 6.3.0...6.3.1
added support for laravel 12, drop support for laravel 10 by @frasmage in #375
Full Changelog: 6.2.1...6.3.0
Fix imageManipulation::outputWebpFormat() encoding by @frasmage in #373
Full Changelog: 6.2.0...6.2.1
Added support for PHP 8.4 by @selfsimilar in #362
Full Changelog: 6.1.3...6.2.0
Migration Class Refactor and Column Existence Check by @anilkumarthakur60 in #358
Full Changelog: 6.1.2...6.1.3
Fix publish add_alt_to_media migration by @jason-nabooki in #353
Full Changelog: 6.1.1...6.1.2
Fix typo in driver class FQCN Full Changelog : 6.1.0...6.1.1
Full Changelog: 6.1.0...6.1.1
Attempt to automatically select an intervention/image driver based on the available extensions.
intervention/image driver based on the available extensions.plank/laravel-mediable and intervention/image-laravel at the same timemove ImageManipulator singleton to lazy instantiation
Fix alt migration default value for the mysql dialect. Default value assigned from the Media model
fix service provider database migration bindings by @frasmage in #349
Added intervention/image-laravel package to the composer suggests list
intervention/image-laravel package to the composer suggests listFix readthedocs documentation build configuration
Dropped support for PHP 7.4 and 8.0
MediableInterfacewithAltAttribute() method to set the alt attribute on the generated media record.MediaUploader::applyImageManipulation() to make changes to the original uploaded image during the upload process.MediaUploader::validateHash() to ensure that the hash of the uploaded file matches a particular value during upload. Supports any hashing algorithm supported by PHP's hash() function.MediaUploader::preferClientMimeType() to indicate that the MIME type provided by the source should be used instead, if provided. The default behaviour can be configured with the 'prefer_client_mime_type' key in the config/mediable.php file.MediaUploader::useHashForFilename() method now accepts an optional parameter to specify which hashing algorithm to use to generate the filename. Supports any hashing algorithm supported by PHP's hash() function.makePublic()/makePrivate() methods are not called, instead of assuming public visibility.data:image/jpeg;base64,....All SourceAdapter classes have been significantly refactored.
temp:// to avoid repeated HTTP requests.getStreamResource() method. The method has been replaced with the getStream(): StreamInterface, which returns a PSR-7 stream implementation instead.hash(string $algo): string method which is expected to return the hash of the file contents using the specified algorithm.filename() and extension() method is now nullable. If the adapter cannot determine the value from the information available, it should return null.getContents() method. The getStream()->getContents() method may be used instead.getSource() method. No replacement.path() method. No replacement.valid() method. SourceAdapters should now throw an exception with a more helpful message from the constructor if the source is not valid.jpegoptim, pngquant, optipng, gifsicle, etc.)config/mediable.php file to specify the optimization tools to use and their arguments.ImageManipulation::noOptimization() and ImageManipulation::optimize(?array $optimizers = null) methods to allow overriding the defaults set in the config file.ImageManipulation::useHashForFilename() method now accepts an optional parameter to specify which hashing algorithm to use to generate the filename. Supports any hashing algorithm supported by PHP's hash() function.ImageManipulation::usingHashForFilename() method has been renamed to ImageManipulation::isUsingHashForFilename() to avoid confusion with the useHashForFilename() method.alt attribute to the Media model.url attribute which will generate a URL for the file (equivalent to the getUrl() method).MediableCollection annotions to support generic types.\Plank\Mediable\Stream class in favor of the guzzlehttp/psr7 implementation. This removes the direct dependency on the psr/http-message library.\Plank\Mediable\HandlesMediaUploadExceptions::transformMediaUploadException() parameter and return type changed from \Exception to \Throwable.Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Filename and pathname sanitization will use the app locale when transliterating UTF-8 characters to ascii.
application/octet-stream (changed in recent version of Flysystem)Fixed S3 temporary URL generation for Laravel 9+ / Flysystem 3+
Dropped support for Laravel 6.x and 7.x
Support specifying file visibility on variant creation
Handle Guzzle stream_for()` deprecation
Allow passing filesystem options via uploader and mover
- Fixed Facade PHPDOC typehints
Added MediaUploader::onDuplicateReplaceWithVariants() which behaves similar to onDuplicateReplace() but will also delete any variants of the replaced
MediaUploader::onDuplicateReplaceWithVariants() which behaves similar to onDuplicateReplace() but will also delete any variants of the replaced Media record.onDuplicateUpdate() failing if file exists but without a matching model.Fixed MediaUploader Facade returning the same instance
MediaUploader Facade returning the same instance- Resolve bugs with PHP 8.0
ImageManipulator now uses $media->contents() instead of $media->stream(), as Intervention Image loads the whole file into memory anyways, and the form
ImageManipulator now uses $media->contents() instead of $media->stream(), as Intervention Image loads the whole file into memory anyways, and the former seems to have fewer hiccups for various cloud filesystems.Fixed serialization of CreateImageVariants job.
CreateImageVariants job.Fixed docblock of attachMedia() and SyncMedia() (Thanks @hailwood!)
attachMedia() and SyncMedia() (Thanks @hailwood!)Fixed additional bugs with the MediableCollection::delete() method
MediableCollection::delete() methodMediableCollection::delete()fixed notices generated from collection offset access in MediableCollection::delete()
MediableCollection::delete()Added support for creating image variants using the intervention/image library. Variants can be created synchronously in the current process or asychr
., -, _, and / for directories). Will automatically attempt to transliterate UTF-8 accented characters and ligatures into their ASCII equivalent, all other characters will be converted to hyphens.Media::stream() method to easily retrieve a PSR-7 compatible Stream.Fixed a handful of bugs related to using a custom table name when using a custom media class
Fixed Morph relation when subclassing Media (Thanks @GeoSot!)
Dropping support for Laravel versions < 6.0
Fix composer version constraint of league/flysystem to allow minor version bumps
league/flysystem to allow minor version bumpsMedia::moveToDisk() and Media::copyToDisk() now correctly transfer file visibility to the new disk.
Media::moveToDisk() and Media::copyToDisk() now correctly transfer file visibility to the new disk.Added Media::moveToDisk() and Media::copyToDisk() methods.
Media::moveToDisk() and Media::copyToDisk() methods.The Media::$size property is now cast as int, fixing a TypeError. (Thanks @boumanb!)
Media::$size property is now cast as int, fixing a TypeError. (Thanks @boumanb!)RemoteUrlAdapter, StreamAdapter, and StreamResourceAdapter potentially returning an incorrect filename and/or extension if the query params of the URL contains certain characters.Fix bug with package auto-discovery with PHP 7.4
Replaced usage of the getClientSize() method deprecated in Symphony 4.1 with getSize()
getClientSize() method deprecated in Symphony 4.1 with getSize()- Added support for Laravel 7.0
Fixed the timing of the beforeSave callback. Now occurs before onDuplicate validation occurs. This allows the callback to be used to determine where t
MediaUploader::replace() and MediaUploader::import() methods as wellAdded support for the new Symfony MimeTypes class in favor of the deprecated ExtensionGuesser (Thanks @crishoj!)
changed UrlGenerators to use the underlying filesystemAdapter's url() method
url() methodMediaUrlException when the file does not have public visibility. This removes the need to read IO for files local disks or to make HTTP calls for files on s3 disks.LocalUrlGenerator::getPublicPath()'prefix' config of local disks. Value should be included in the 'url' config instead.Fixed public visibility not being respected when generating URLs for local files that are not in the webroot.
Updated minimum support requirements to PHP 7.2 and Laravel 5.6+.
getStreamResource to SourceAdapterInterface, uploader will now attempt to use a stream to reduce memory usage.delete() method to MediableCollection for mass deleting media records and files.The name of the Mediables pivot table is now configurable (Thanks @nadinengland!)
Fix windows paths pattern (Thanks @aalyusuf!)
Add methods to facade for IDE autocompletion (Thanks @simonschaufi!)
Your coding agent can read these notes before it upgrades. Set up the MCP server →