shouldiuse.io

Report

Should I Use Amasty?

amasty.com·Analyzed 1 day ago··Based on 9 sources

Magento 2 extension vendor

Depends

Depends

Worth buying if you run Magento 2 and need a specific feature, with a developer who applies security patches fast.

Magento-only extension powerhouse with a huge catalog — but a public RCE exploit and 25-extension patch wave demand fast patching.

Confidence: Medium

4.3/5

Trustpilot

627 reviews

3.4/5

G2 vendor rating

7 reviews

~$20M

Revenue

Owler estimate

Bootstrapped

Funding

No outside investment

Value for money2

Reddit users call pricing a 'money grab'

Feature depth4

Vast catalog: checkout, SEO, security, segmentation

Support quality3

Trustpilot 4.3/627 positive; Reddit reports mixed

Security posture2

RCE CVE plus 25-extension mass patch release

Pros

  • Huge catalog of Magento 2 extensions across sales, UX, and admin¹
  • Established Adobe Commerce vendor, ~$20M revenue, no debt to investors
  • Trustpilot 4.3/5 across 627 reviews²
  • Does patch disclosed vulnerabilities — 25 extensions fixed in one release
  • Moving Hyvä-first for faster storefronts

Cons

  • CVE-2026-53787: unauthenticated file upload leading to remote code execution
  • Fully weaponized public exploit for that RCE exists
  • Mass patch release across 25 extensions, 2 rated critical
  • Community complaints about pricing becoming a 'money grab'
  • G2 vendor rating is only 3.4/5³

Gotchas

  • highPublic weaponized exploit for Order Attributes RCE — patch immediately or risk store compromise
  • mediumRenewal fees and aggressive upsells; Reddit calls recent pricing moves a 'money grab'
  • mediumCompatibility issues reported; Custom Forms allegedly fails to trigger Trustpilot AFS
  • lowCommunity sentiment on extension vendors is mixed — vet each module separately before buying

Best for

  • Mid-market Magento 2 stores
  • Stores needing niche checkout or SEO features
  • Adobe Commerce teams with dev resources
  • Hyvä-theme adopters

Not for

  • Shopify or WooCommerce stores — this is Magento-only
  • Solo merchants with no Magento developer on call
  • Teams that won't patch extensions within days of disclosure
  • Buyers sensitive to aggressive renewal and upsell pricing

Security

Recent critical findings: unauthenticated RCE (CVE-2026-53787) in Order Attributes and a mass patch release across 25 extensions; vendor is patching actively.

  • CVE-2026-53787 — Unauthenticated arbitrary file upload / RCE in Order AttributesUnauthenticated file upload in versions below 4.0.0 enables remote code execution; a weaponized exploit is publicly available.
  • Mass security patch release across the extension catalogAmasty patched 25 extensions after coordinated disclosures; 2 issues were rated critical.

What users say

Opinions split: long-time users praise the modules, while others complain about pricing moves and integration glitches.

So Amasty have gone full money grab with their
Reddit, r/Magento
I can only say good things about Am
Reddit, r/Magento
Amasty review module is best
Review snippet, Amasty listing

Alternatives

Compare Amasty with each alternative.

Aheadworks

Longtime Magento extension vendor users compare side-by-side

Full analysis

Based on 20+ public sources including G2, Trustpilot, Sansec, GitHub, and Reddit threads

Sources

  1. official
  2. review
  3. review
  4. security
  5. security
  6. security
  7. review
  8. news
  9. news

Rate this review

Anonymous. You can change your vote.

Loading votes…

Ask a follow-up

Ask if a use case fits. Answers stay inside this report and its sources.

    Comments

    One queue. No replies. Give a display name first. Limit: 7 comments per day.

    Save a name to write a comment.

    No comments yet.