shouldiuse.io

VERDICT

Should I use ToolJet?

Explore insights, tutorials, and updates on low-code development and application creation. - blog.tooljet.com

Depends. Buy if your engineering team builds internal tools and wants open-source control with builder-only pricing. Skip it if you're non-technical, want zero-maintenance hosting, or can't keep up with an active CVE queue.

Confidence

Medium. Based on 40+ public sources; most snippets were truncated, so some quotes couldn't be verified verbatim.

Ratings

  • Value for money
  • Ease of use
  • Feature depth
  • Support qualityNo direct support evidence in sources
  • Security posture

Pricing

Free, open source

Community (self-hosted)

ModelNot disclosed
Monthly feesNot disclosed
HardwareNot disclosed
Free tierYes
Paid / EnterpriseBuilder-only billing; one 2025 review cites ~$240/yr entry

Best for

  • Engineering teams building internal tools
  • Self-hosters wanting data control
  • Retool refugees watching spend
  • AI-assisted CRUD app builders

Not for

  • Non-technical teams wanting a polished hosted builder
  • Orgs that can't patch fast (active 2026 CVE queue)
  • Overkill: simple lists a spreadsheet or Airtable covers
  • Customer-facing products (built for internal tools)

Gotchas - check before you buy

high

Marketplace plugin poisoning CVE exists — vet third-party components before installing

medium

Guess: open-source edition means you own upgrades, backups, and urgent CVE patching

medium

Cloud Run and similar deployments need manual setup — budget ops time

low

Builder-only pricing looks cheap; value depends on your actual builder count

Pros and cons

Pros

  • Open-source with ~25k GitHub stars; free to self-host
  • Builder-only pricing — end users don't cost extra
  • AI-assisted app building called a strength in comparisons
  • SOC 2, ISO 27001, and GDPR compliance documented
  • Named enterprise case studies across fintech, edtech, retail

Cons

  • Multiple 2026 CVEs, including authentication bypasses
  • Pre-v3.16.208 installs exposed cross-organization data
  • Self-hosting requires manual cloud deployment config
  • Some open-source rivals ship more components

Sources & method

Analyzed 9/20/2026 - 14 sources - SOC 2 and ISO 27001 claimed, but 2026 brought several CVEs including two auth bypasses — patch discipline is mandatory.

official x4review x5security x4news x1
  • CVE-2026-82870: Authentication bypass, Authentication bypass vulnerability disclosed in 2026.
  • CVE-2026-73068: Authentication bypass, Second auth bypass CVE tracked on NVD in 2026.
  • CVE-2026-82872: Cross-org data read, Versions before v3.16.208 failed to prevent cross-organization data reads.
  • CVE-2026-55413: Marketplace plugin poisoning, Plugin poisoning issue in the marketplace ecosystem.
  • CVE-2026-82869: ToolJet Database flaw, ToolJet Database versions before v3.16.44 affected.

Key stats

  • Value for money: 4/5

    Rating

  • Free, open source

    Starting price

  • 14

    Sources

  • Analyzed

  • Value for money: 4/5. Free open-source core; builder-only billing keeps seats cheap
  • Ease of use: 4/5. AI builder praised; self-host setup takes real work
  • Feature depth: 4/5. Enterprise apps, built-in database, AI agents
  • Support quality. No direct support evidence in sources
  • Security posture: 2/5. SOC 2/ISO claimed, but multiple 2026 CVEs incl. auth bypass
  • 4+/5 G2 rating 53 reviews across ToolJet products
  • Free (open source) Starting price Paid plans bill builders only
  • Yes Free tier Self-hosted community edition
  • $6.15M+ Funding $1.55M seed + $4.6M pre-A, plus M12/GitHub

Pricing

Community (self-hosted)

Free, open source

  • Unlimited self-managed use
  • You handle hosting and updates

Paid / Enterprise

Builder-only billing; one 2025 review cites ~$240/yr entry

  • Managed hosting options
  • Enterprise controls and scale

Security

SOC 2 and ISO 27001 claimed, but 2026 brought several CVEs including two auth bypasses — patch discipline is mandatory.

  • CVE-2026-82870: Authentication bypassAuthentication bypass vulnerability disclosed in 2026.⁷
  • CVE-2026-73068: Authentication bypassSecond auth bypass CVE tracked on NVD in 2026.
  • CVE-2026-82872: Cross-org data readVersions before v3.16.208 failed to prevent cross-organization data reads.⁸
  • CVE-2026-55413: Marketplace plugin poisoningPlugin poisoning issue in the marketplace ecosystem.⁹
  • CVE-2026-82869: ToolJet Database flawToolJet Database versions before v3.16.44 affected.

What users say

G2 reviewers rate ToolJet around 4/5, and Reddit/Medium comparisons consistently frame it as a cheaper open-source Retool alternative.

Alternatives

Compare ToolJet with each alternative.

  • Lowcoder

    Open-source alternative with more components

Companies that use it

  • Emeritus
  • Toss
  • FrankieOne
  • Pizza Pizza
Full analysis

Based on 40+ public sources; most snippets were truncated, so some quotes couldn't be verified verbatim.

Strong open-source Retool alternative for internal tools — best if you can self-host and patch fast.

Methodology

Based on 40+ public sources; most snippets were truncated, so some quotes couldn't be verified verbatim.

Sources

  1. review
  2. review
  3. official
  4. ToolJet homepagetooljet.com
    official
  5. ToolJet pricingtooljet.com
    official
  6. ToolJet compliance docsdocs.tooljet.com
    security
  7. security
  8. security
  9. security
  10. review
  11. review
  12. news
  13. official
  14. review

Rate this review

Anonymous. You can change your vote.

Loading votes…

Comments

One queue. No nested comments. Give a display name first. Limit: 200 words per comment and 7 comments per day. You can edit or delete yours.

Save a name to write a comment.

0 / 200 words

No comments yet.