shouldiuse.io

Categories

VERDICT

Altova Review

Depends

Should I use Altova?

XML, data integration, and mobile app development tools (XMLSpy, MapForce, MissionKit) - altova.com

· 8 hours ago

Buy if your team works daily in XML/JSON, EDI mapping, or XBRL — the toolkit is deep and battle-tested. Skip it for light data wrangling or cloud-scale integration; simpler or cheaper tools fit better.

Confidence

Medium. Based on ~30 public sources; many review snippets truncated, so user sentiment is thin.

Ratings

  • Value for moneyNo public pricing found in sources
  • Ease of use
  • Feature depth
  • Support qualityNo support-quality evidence found
  • Security posture

Pricing

Free

Authentic

ModelNot disclosed
Monthly feesNot disclosed
HardwareNot disclosed
Free tierYes
Desktop tools / MissionKitPer-seat; not published in sources
Server productsNot published in sources

Best for

  • XML/JSON-heavy dev teams
  • EDI data-mapping work
  • XBRL and regulatory reporting
  • One-off data-migration projects

Not for

  • Quick one-off CSV/XML conversions — overkill
  • Enterprise cloud integration at scale
  • Non-technical teams wanting no-code iPaaS
  • Tight budgets — automation needs separately licensed Server products

Gotchas - check before you buy

high

Guess: production automation requires MapForce Server, licensed separately from desktop MapForce

high

Keep MobileTogether Server patched — XXE flaw pre-7.3 SP1 had public exploit

medium

Licenses sold in 1-, 2-, or 3-year terms; renewal costs accumulate

low

Small review base makes support quality hard to verify pre-purchase

Pros and cons

Pros

  • Capterra calls XMLSpy the leading XML editor
  • Visual, code-free data mapping across XML, databases, EDI, Excel
  • Broad purpose-built kit: mapping, databases, mobile apps, XBRL
  • Claimed 5.6 million users; established niche player
  • 4.3/5 seller rating across 61 G2 reviews

Cons

  • Critical XXE vulnerability in MobileTogether Server before 7.3 SP1
  • Public exploit code exists for that MobileTogether flaw
  • Glowing 5.0 ratings rest on just 3 reviews
  • Comparisons position MapForce Server behind SnapLogic for integration
  • No public pricing on most pages; buy via shop or resellers

Sources & method

- 14 sources - Known CVEs including one critical XXE (patched in 7.3 SP1); maintain strict patch discipline on server products.

official x3review x6security x3news x2
  • CVE-2021-37425 — XXE in MobileTogether Server, XML external entity injection in versions before 7.3 SP1; rated critical, public exploit published August 2021.
  • CVE-2010-5271 — untrusted search path, Older untrusted search path vulnerability in an Altova product.
  • Infostealer credentials tied to altova.cloud, Hudson Rock lists 8 infostealer credentials referencing the domain — user-side credential exposure indicator, not a confirmed product breach.

Key stats

  • Ease of use: 4/5

    Rating

  • Free

    Starting price

  • 14

    Sources

  • Analyzed

  • Value for money. No public pricing found in sources
  • Ease of use: 4/5. Visual mapping praised; review samples tiny
  • Feature depth: 5/5. Suite spans XML, mapping, DBs, mobile, XBRL
  • Support quality. No support-quality evidence found
  • Security posture: 2/5. Critical 2021 XXE CVE; patch discipline required
  • 4.3/5 G2 seller rating 61 reviews
  • 5.0/5 MapForce rating Only 3 reviews (GetApp)
  • 5.6M Claimed users Per Altova company page
  • ~$5M/yr Estimated revenue Growjo estimate

Pricing

Authentic

Free

  • No-charge viewer/editor license per EULA
  • Entry-level XML/JSON viewing

Desktop tools / MissionKit

Per-seat; not published in sources

  • MissionKit bundles XMLSpy, MapForce, StyleVision
  • 1-, 2-, or 3-year license terms
  • Buy via shop.altova.com or resellers

Server products

Not published in sources

  • MapForce Server, RaptorXML for automation
  • Positioned against SnapLogic and TIBCO

Security

Known CVEs including one critical XXE (patched in 7.3 SP1); maintain strict patch discipline on server products.

  • CVE-2021-37425 — XXE in MobileTogether ServerXML external entity injection in versions before 7.3 SP1; rated critical, public exploit published August 2021.⁶
  • CVE-2010-5271 — untrusted search pathOlder untrusted search path vulnerability in an Altova product.
  • Infostealer credentials tied to altova.cloudHudson Rock lists 8 infostealer credentials referencing the domain — user-side credential exposure indicator, not a confirmed product breach.⁸

What users say

Feedback is sparse but mostly positive: praise for XML tooling and data mapping, with a 4.3/5 seller rating across 61 G2 reviews.

“I have had luck with DiffDog”
Reddit, r/Python

Companies that use it

  • Equifax11
  • US Navy (via Wrycan)
  • NYC & Company
  • National Frozen Foods
Full analysis

Based on ~30 public sources; many review snippets truncated, so user sentiment is thin.

Deep, pricey specialist toolkit for XML/data mapping; overkill for simple jobs. Known CVEs — patch servers.

Methodology

Based on ~30 public sources; many review snippets truncated, so user sentiment is thin.

Read how a report is made.

Sources

  1. review
  2. review
  3. review
  4. review
  5. review
  6. security
  7. security
  8. security
  9. official
  10. official
  11. official
  12. news
  13. news
  14. review

Rate this review

Anonymous. You can change your vote.

Loading votes…

Comments

One queue. No nested comments. Give a display name first. Limit: 200 words per comment and 7 comments per day. You can edit or delete yours.

Save a name to write a comment.

0 / 200 words

No comments yet.