We stand with Ukraine to help keep people safe. Join us
EN
When you purchase through links on our site, we may earn an affiliate commission
HomeBusinesspgAdmin 4

pgAdmin 4 for Mac

Administration and development for PostgreSQL database.

Free
In English
5.0
Based on 3 user rates

pgAdmin 4 overview

pgAdmin is the a popular and feature rich Open Source administration and development platform for PostgreSQL, the most advanced Open Source database in the world. The application may be used on Linux, FreeBSD, Solaris, Mac OSX and Windows platforms to manage PostgreSQL 7.3 and above running on any platform, as well as commercial and derived versions of PostgreSQL such as Postgres Plus Advanced Server and Greenplum database.

pgAdmin is designed to answer the needs of all users, from writing simple SQL queries to developing complex databases. The graphical interface supports all PostgreSQL features and makes administration easy. The application also includes a syntax highlighting SQL editor, a server-side code editor, an SQL/batch/shell job scheduling agent, support for the Slony-I replication engine and much more. Server connection may be made using TCP/IP or Unix Domain Sockets (on *nix platforms), and may be SSL encrypted for security. No additional drivers are required to communicate with the database server.

pgAdmin is developed by a community of PostgreSQL experts around the world and is available in more than a dozen languages. It is Free Software released under the PostgreSQL License.

What's new in version 9.18

New features
  • Issue #9631 - Collapse and restore the Object Explorer by re-clicking the current workspace icon, in the manner of the VS Code side bar, remembering the choice across refreshes. A keyboard shortcut, Ctrl+Alt+B by default, does the same thing and can be changed through the new toggle_object_explorer preference.
Housekeeping
  • Issue #10221 - Skip importing and initialising the kerberos, ldap, mfa, oauth2 and webserver authentication providers unless SERVER_MODE is set, leaving desktop mode with internal authentication alone.
  • Issue #10247 - Relax the azure-mgmt-resource pin to allow 24.0.0, and aggregate the third-party JavaScript and Python dependency bumps for this release.
  • Issue #10293 - Make the Schema Diff regression test assert its own generated script, which it previously swallowed, so invalid generated SQL can no longer pass silently.
Bug fixes
  • Issue #9226 - Accept SharedUsername when importing a shared server from a servers.json definition, instead of insisting on Username for every server.
  • Issue #10155 - Share concurrent identical GET requests behind getNodeAjaxOptions() so a wide table’s Columns tab no longer fires one duplicate get_types request per column row.
  • Issue #10179 - Fix inherited columns in the Table dialog being editable and deletable: a column already inherited from a parent carries inheritedfromtable while one fetched interactively through ‘Inherited from table(s)’ carries inheritedfrom and has no attnum yet, and only the latter was checked, after an isNew() short-circuit that treated the attnum-less rows as new.
  • Issue #10180 - Fix the Data type dropdown on the expanded Definition tab of the Table dialog offering every type, ignoring the allowed-type restriction already applied to the inline editor.
  • Issue #10214 - Fix the existingSecret path in the Helm deployment template.
  • Issue #10235 - Remove a trailing quote from the Windows installer’s ProductVersion, which was stamped as e.g. 9.17".
  • Issue #10236 - Fix Schema Diff reporting false differences for SERIAL/BIGSERIAL columns by ignoring the owned sequence’s oid, and fix the invalid ALTER COLUMN ... TYPE bigserial SQL generated when such a column genuinely differs.
  • Issue #10237 - Fix a replace() argument 2 must be str, not None crash when a per-server Password Exec Command is used with a service-only (pg_service.conf) connection, which leaves host, port and username unset.
  • Issue #10239 - Remove a redundant passlib pin that conflicts with the indirectly required libpass.
  • Issue #10252 - Fix the argument grid on the Definition tab of a user-defined function or procedure refusing to delete, or add, a row in edit mode.
  • Issue #10295 - Reinstate dependency ordering of the script Schema Diff generates, which had been lost since the React port left dependLevel unset.
  • Issue #10297 - Fix Schema Diff duplicating any column that also differs when it recreates a foreign table.
  • Issue #10298 - Fix Schema Diff generating SQL that PostgreSQL rejects when a sequence’s MINVALUE is raised above its current value.
  • Issue #10300 - Fix a foreign table column added by Schema Diff losing its collation.
  • Issue #10302 - Fix Schema Diff injecting whitespace into an applied function or procedure body, which left a whitespace-only difference behind.
  • Issue #10303 - Report a Schema Diff comparison that fails part way through as a failure, rather than as a success.
  • Issue #10309 - Reject an empty or null Username when importing a non-shared server, which previously imported cleanly and left a server libpq would silently authenticate as the OS account running pgAdmin.
  • Issue #10311 - Fix login being impossible against Flask-Security-Too 5.8.2, which corrected a long-standing inversion in UserMixin.is_locked() that User.is_locked() had been written against.
  • Issue #10341 - Omit the redundant TABLESPACE pg_default clause from generated index SQL, which was invalid on a partitioned table.
  • Issue #10383 - Fix an authentication bypass in Webserver authentication mode, where get_user() fell back to reading the configured WEBSERVER_REMOTE_USER name from the request headers when it was absent from the WSGI environment, letting any client that could reach pgAdmin assert any identity, including an administrator’s (CVE-2026-86863). Header-asserted identity is now opt-in, restricted to a configured list of trusted proxies with an optional shared secret, and refused for accounts whose authentication source is not webserver. Reported by Sanghyeon Lee (@h9e0n).
  • Issue #10384 - Fix argument and connection-string injection in the Backup tool, where the client-supplied database name was appended to the pg_dump argument vector as a bare positional argument: because getopt_long permutes arguments, a value beginning with a dash supplied further options such as --file, overriding the storage-confined output path, and because libpq expands a database name containing an equals sign into a full connection string, one could also redirect the connection to an attacker-controlled host and exfiltrate the stored password (CVE-2026-86864). The database name is now passed through the PGDATABASE environment variable instead. Reported by Sanghyeon Lee (@h9e0n) and Hitesh Jambhale.
  • Issue #10385 - Fix a time-of-check to time-of-use flaw in the File Manager’s save_file endpoint, which backs saving from the Query Tool and ERD: the requested path was validated with check_access_permission() and then opened with a plain open(), so a symbolic link planted in between was followed, writing outside the storage directory. This is the sink CVE-2026-7819’s hardening of the separate upload path did not cover (CVE-2026-86861). Reported by sec-rex.
  • Issue #10388 - Fix connection-string injection in the Restore and Maintenance tools, where the client-supplied database name was passed straight to --dbname: libpq expands a database name containing an equals sign into a full connection string, whose embedded keywords override the --host and --port pgAdmin supplies, so the connection - and the stored password exported in PGPASSWORD - could be redirected to a server of the caller’s choosing (CVE-2026-86862). The database name is now passed through the PGDATABASE environment variable, which libpq never expands. Found by Hitesh Jambhale.
  • Issue #10393 - Render the Validate binary path dialog as HTML, instead of showing the raw markup.
  • Issue #10420 - Refuse HTTP redirects on LLM API requests, rather than following a Location header on to a destination ALLOWED_LLM_API_URLS was never applied to. This is hardening rather than a fix for an exploitable flaw, since returning the redirect at all requires control of a host already on the allowlist. Reported by Ziya Abdullayev.

Full list of changes available here

View older pgAdmin 4 versions

pgAdmin 4 for Mac

Free
In English
Version 9.18
Write a detailed review about pgAdmin 4

Write your thoughts in our old-fashioned comment

MacUpdate Comment Policy. We strongly recommend leaving comments, however comments with abusive words, bullying, personal attacks of any type will be moderated.
5.0

(1 Reviews of pgAdmin 4)

  • Comments

  • User Ratings

coolwholesaless
coolwholesaless
Jun 6, 2025
9.4
0.0
Jun 6, 2025
0.0
Version: 9.4
good
reggiesmith004
reggiesmith004
May 24, 2025
9.3
5.0
May 24, 2025
5.0
Version: 9.3
makareim
makareim
May 2, 2025
9.3
5.0
May 2, 2025
5.0
Version: 9.3
Ervins Strauhmanis
Ervins Strauhmanis
Apr 30, 2025
9.1
5.0
Apr 30, 2025
5.0
Version: 9.1