# Studio-42/elFinder: a jQuery file manager you host yourself

> elFinder is a browser file manager with a PHP connector, a JSON API and multi-root volume drivers. It fits projects that already run PHP and want Finder-style file operations inside their own admin, and it is a poor fit if you need a standalone, non-PHP service.

**Studio-42/elFinder** — 📁 Open-source file manager for web, written in JavaScript using jQuery and jQuery UI

- Repository: https://github.com/Studio-42/elFinder
- Website: https://studio-42.github.io/elFinder/
- Stars: 4,805 · Forks: 1,430
- Language: JavaScript
- License: NOASSERTION
- Published: 2026-09-23 · Updated: 2026-09-23 · Language: en
- Canonical page: https://hysenlabs.com/projects/studio-42-elfinder

## What elFinder solves, and for whom

The project is a web file manager written in JavaScript with jQuery and jQuery UI, and its stated inspiration is the Finder program in Mac OS X. That framing matters: it is not a storage service, a sync client or a document collaboration tool. It is a user interface plus a server connector that exposes file and folder operations on a remote server through the browser. The README lists copy, move, upload, create folder or file, and rename as the operations it handles.

The audience is narrow and specific. If you already have a PHP application and you need users to browse, upload, rename, archive or preview files without leaving your admin interface, elFinder drops into that slot. It ships with integration notes for web editors (elRTE, CKEditor, TinyMCE), which tells you the intended context is an existing content or management application rather than a standalone product. Multi-root support and configurable access rights point the same way: you are expected to decide which folders each user sees.

Where it is the wrong tool is equally clear. There is no hosted offering, no account system of its own, and the client is built on jQuery and jQuery UI. A team on a modern component framework with no PHP runtime will spend more time adapting the connector than writing their own upload endpoint.

## The connector, the JSON API and the volume drivers

The architecture has two halves. The client is the jQuery UI interface in js/ and css/, loaded by one of the HTML entry points in the repository root (elfinder.html, elfinder.src.html, elfinder-minimal.html, elfinder.legacy.html). The server half is the PHP connector under php/, which the README describes as a simple client-server API based on JSON. The client does not touch the filesystem; every listing, rename and upload goes through the connector.

Storage is abstracted as volumes. The README lists local file system, MySQL, FTP, SFTP, Box, Dropbox, GoogleDrive and OneDrive as volume storage drivers, and notes that AWS S3, Azure and Digital Ocean Spaces are reachable through the League\Flysystem driver, which is a third-party connector rather than something bundled. Multi-root support means one elFinder instance can present several of these at once, so a user could see a local folder and a Dropbox folder in the same tree.

Several connector plugins sit on the server side and act on upload: AutoRotate corrects JPEG orientation from EXIF, AutoResize resizes on upload, Normalizer handles UTF-8 file names and paths, Sanitizer cleans file names and paths, and Watermark stamps uploaded files. These are PHP plugins in php/plugins/, not client features, so they apply regardless of which browser is used. Chunked upload is listed for large files, and drag and drop upload is described as background HTML5 upload.

## Installing elFinder on a PHP server

The README gives two paths. For a compressed build, download and unzip a release onto a PHP server, rename the connector template, and open the bundled HTML page. The repository also documents a source install. Both paths require the same rename step, and skipping it is the most common reason a fresh copy returns nothing useful.

To install from source, clone the repository onto a PHP server:

```bash
$ git clone https://github.com/Studio-42/elFinder.git
```

Then rename /php/connector.minimal.php-dist to /php/connector.minimal.php. According to the README, loading /elfinder.src.html in the browser after that runs elFinder. The compressed build differs only in the entry page: you load /elfinder.html instead. The repository also points to a Composer-based installer page for setting up the 2.1.x nightly.

The requirements section is worth reading before you start. The client needs jQuery 1.8.0 or higher and jQuery UI 1.9.0 or higher, with draggable, droppable, resizable, selectable, button and slider required, and sorter recommended so that list columns and Places can be sorted. The server side needs any web server and PHP 5.2 or higher, with PHP 5.4 or higher recommended. Thumbnails require the GD or Imagick module, or convert from ImageMagick. For non-ASCII characters in file paths and names on a Windows server, the README recommends PHP 7.1 or higher.

A minimal volume configuration in the connector follows the multi-root model: each root is an array entry with a driver and a path. The README does not print a full connector example, so treat the shipped connector.minimal.php-dist as the reference and edit it in place rather than writing one from scratch.

## The security warning the project puts above everything else

The first thing in the README is not a feature list. It is a warning in capitals: if you have older versions of elFinder, in particular 2.1.69 or earlier, on public servers, it may cause serious damage to your server and to visited users, and you should update to the latest version or remove it from the server. That is unusually blunt for a project README, and it should shape how you evaluate elFinder.

A file manager is a high-value target. It accepts uploads, it renames and moves files, and it can extract archives. Any flaw in path handling or upload validation is directly reachable from the browser. The project's own warning confirms that this class of bug has occurred and that the fix is version-bound. The practical consequence is that elFinder is not a set-and-forget dependency. If you cannot commit to tracking releases and applying them, the risk profile is worse than a component that only renders data.

The warning also implies a review step for anyone running an older deployment. The README does not document a migration procedure or a rollback path for the connector, so the safe assumption is that upgrading means replacing the connector and client files together. Version 2.0.9 is labelled deprecated in the downloads list, which reinforces that the maintained line is 2.1.x.

## Maintenance cadence, licence and upgrade cost

The repository is not archived, and the last push was on 2026-08-03. Recent releases follow a steady pattern: 2.1.68 and 2.1.69 both landed on 2026-05-07, and 2.1.70 on 2026-08-03. That is roughly a quarterly rhythm with occasional paired releases, which is a reasonable cadence for a mature project but not a fast one.

Upgrade cost depends on how much you have customised. The connector is a PHP file you edit directly, and the plugins live in the same tree, so local changes have to be reapplied on each update. If you rely on third-party volume drivers or connectors, a release can move under them. The README does not describe a supported upgrade path, a deprecation policy or a compatibility matrix, so plan on reading the Changelog for every version you skip.

On licensing, the badge in the README points at BSD-3-Clause, and package.json declares "license": "BSD-3-Clause". The repository metadata reports NOASSERTION, which is a mismatch worth resolving with whoever approves dependencies in your organisation. BSD-3-Clause is permissive and generally allows commercial use and modification with the copyright notice retained, but the bundled jQuery and jQuery UI components may carry their own terms, and the README does not enumerate them. That is a question for your legal reviewer, not something to assume from the top-level licence file.

## Alternatives and where the approach differs

The obvious comparison is a general-purpose file manager such as Tiny File Manager: a single PHP script that you drop on a server and protect with a password, with no build step and no jQuery UI client. elFinder is heavier in both directions. It gives you a desktop-like interface, multi-root volumes, cloud drivers and a plugin layer, and it asks for jQuery, jQuery UI, a connector you configure, and a build step if you want the compressed distribution. If all you need is to move a few files on a server you administer, the single-script approach is less to maintain and less to expose.

If your application is not PHP, the calculus changes entirely. The connector is PHP; a Node, Python or Go service cannot use it without a rewrite, and rewriting it means reimplementing the JSON API, the volume drivers and the plugin hooks. In that case a purpose-built upload component for your framework is the smaller project. The README does not document a non-PHP reference connector, so this is not a matter of swapping a driver.

There is also a middle path the README hints at rather than documents: the client and connector are separable in principle, so a team could keep the jQuery UI front end and write their own backend against the same JSON API. That is real work, and the README does not publish the API in enough detail here to judge how much.

## Conclusion

Adopt elFinder if you run PHP and need file operations embedded in an existing admin panel, and you can take on the upgrade discipline the project itself demands. Do not adopt it if you need a standalone service in a non-PHP stack or a manager that works without a server-side connector. Before committing, verify the exact version you deploy against the project's own warning about older releases on public servers, and confirm that the connector file has been renamed from connector.minimal.php-dist and that your PHP build has GD, Imagick or convert available if you want thumbnails.

## FAQ

### What is elFinder used for?

It is an open-source web file manager that lets users browse and modify files on a remote server from the browser, with operations such as copy, move, upload, create folder or file, and rename. It is typically embedded in an existing PHP application or admin panel.

### What is a good elFinder alternative?

It depends on why you are leaving. If you only need basic file operations on a server you administer, a single-script PHP file manager avoids the jQuery UI client and the connector configuration. If your stack is not PHP, a framework-specific upload component is a better fit, because the elFinder connector is written in PHP.

### How do I install elFinder?

Clone the repository to a PHP server, rename /php/connector.minimal.php-dist to /php/connector.minimal.php, and load /elfinder.src.html in the browser. For a compressed build, unzip a release, do the same rename, and load /elfinder.html instead.

### What are the server requirements for elFinder?

Any web server plus PHP 5.2 or higher, with PHP 5.4 or higher recommended. Thumbnails need the GD or Imagick module or ImageMagick's convert, and the README recommends PHP 7.1 or higher for non-ASCII file paths and names on Windows servers.

### Why does the elFinder README warn about older versions?

The README states that older versions, in particular 2.1.69 or earlier, may cause serious damage to your server and to visited users if left on public servers, and tells you to update to the latest version or remove it. Treat the version you deploy as a security decision rather than a convenience one.

## Sources

- [Issues](https://github.com/Studio-42/elFinder/issues)
- [Project website](https://studio-42.github.io/elFinder/)
- [README](https://github.com/Studio-42/elFinder/blob/master/README.md)
- [Releases](https://github.com/Studio-42/elFinder/releases)
- [Studio-42/elFinder on GitHub](https://github.com/Studio-42/elFinder)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/studio-42-elfinder
