shouldiuse.io

Categories

VERDICT

Should I use Chatwoot?

Open-source, AI-powered customer support platform - chatwoot.com

Depends. Buy if you're technical and want an open-source, omni-channel support desk at a fraction of Zendesk/Intercom cost. Avoid if you need hands-on vendor support, zero-maintenance SaaS, or can't patch promptly.

Confidence

Medium. Based on 25+ public sources: G2, GitHub, NVD/CVE databases, vendor pages, pricing comparisons, and Reddit.

Ratings

  • Value for money
  • Ease of use
  • Feature depth
  • Support quality
  • Security posture

Pricing

Free

Self-hosted (Community)

ModelNot disclosed
Monthly feesNot disclosed
HardwareNot disclosed
Free tierYes
Startups (Cloud)$19/agent/mo
EnterprisePaid license / custom

Best for

  • Startups ditching expensive Intercom/Zendesk bills
  • Technical teams wanting self-hosted data control
  • Omni-channel support (chat, email, WhatsApp)
  • Open-source advocates

Not for

  • Non-technical teams — self-hosting and patching need real DevOps
  • Buyers needing guaranteed vendor SLAs and hand-holding support
  • Teams that won't patch fast during active CVE waves
  • Anyone wanting zero-maintenance SaaS only

Gotchas - check before you buy

high

Multiple CVEs in 2026 (SQLi, SSRF, auth bypass) mean self-hosters must patch fast.

medium

Captain AI runs on paid credits; AI-heavy teams see costs climb beyond the per-agent price.

medium

Self-hosted edition excludes some enterprise features; those require a paid license.

medium

Support is community-first; one GitHub user reported 'zero support'.

Pros and cons

Pros

  • Open-source and self-hostable with a free community edition
  • Cloud pricing from $19/agent/mo
  • Users love the easy setup
  • Omni-channel: live chat, email, and more in one dashboard
  • SOC 2 Type II compliant

Cons

  • Multiple 2026 CVEs: SQL injection, SSRF, authentication bypass
  • GitHub complaint of 'zero support' from the project
  • Self-hosted sites flagged 'deceptive' by Google in one report
  • Small vendor (~$870K est. ARR) limits support and R&D depth
  • Enterprise features gated behind a paid license even when self-hosting

Sources & method

Analyzed 10/02/2026 - 14 sources - SOC 2 Type II compliant, but several 2026 CVEs (SSRF, SQL injection, auth bypass) require prompt patching, especially if self-hosting.

official x2review x6security x4news x2
  • CVE-2026-92527 — Shopify OAuth SSRF, Server-side request forgery in the Shopify OAuth callbacks controller, affecting chatwoot versions up to 4.11.2.
  • CVE-2026-44706 — SQL injection in FilterService, SQL injection in the Conversation/Contact Filter API, also tracked as GHSA-9pgm-75gg-6948 (May 2026).
  • CVE-2026-4990 — Authentication bypass in Signup, Authentication vulnerability in the signup flow, rated 6.9 (March 2026).

Key stats

  • Value for money: 5/5

    Rating

  • Free

    Starting price

  • 14

    Sources

  • Analyzed

  • Value for money: 5/5. Free self-hosted; cloud from $19/agent/mo
  • Ease of use: 4/5. Reviewers praise easy setup
  • Feature depth: 4/5. Omni-channel inboxes, Captain AI, audit logs, enterprise edition
  • Support quality: 2/5. GitHub 'zero support' complaint; community-dependent
  • Security posture: 2/5. SOC 2 Type II, but multiple 2026 CVEs including SQLi
  • 4.5/5 G2 rating 16 reviews
  • $19/agent/mo Starting price 'Startups' cloud plan
  • Yes Free tier Open-source self-hosted edition
  • 15,000+ orgs Customers Per Chatwoot's pricing page

Pricing

Self-hosted (Community)

Free

  • Run on your own infrastructure
  • Open-source
  • Community support

Startups (Cloud)

$19/agent/mo

  • Managed cloud
  • Per-agent pricing
  • Captain AI billed via credits

Enterprise

Not disclosed

  • Unlocks enterprise features when self-hosting
  • Custom terms

Security

SOC 2 Type II compliant, but several 2026 CVEs (SSRF, SQL injection, auth bypass) require prompt patching, especially if self-hosting.

  • CVE-2026-92527 — Shopify OAuth SSRFServer-side request forgery in the Shopify OAuth callbacks controller, affecting chatwoot versions up to 4.11.2.⁷
  • CVE-2026-44706 — SQL injection in FilterServiceSQL injection in the Conversation/Contact Filter API, also tracked as GHSA-9pgm-75gg-6948 (May 2026).⁸
  • CVE-2026-4990 — Authentication bypass in SignupAuthentication vulnerability in the signup flow, rated 6.9 (March 2026).⁹

What users say

Users praise the easy setup and value, but some report weak support and self-hosting friction.

“Users love the easy setup of Chatwoot”
G2 reviews
“Chatwoot is a wonderful tool for custome”
G2 reviews
“Pretty disappointed in this project - zero support”
GitHub discussion

Companies that use it

  • FairDee (Thailand)
  • Ponea Health
  • Bakingo
Full analysis

Based on 25+ public sources: G2, GitHub, NVD/CVE databases, vendor pages, pricing comparisons, and Reddit.

Open-source Zendesk/Intercom alternative: cheap and flexible, but self-hosting, patching, and thin support demand technical muscle.

Methodology

Based on 25+ public sources: G2, GitHub, NVD/CVE databases, vendor pages, pricing comparisons, and Reddit.

Sources

  1. review
  2. review
  3. official
  4. Chatwoot Pricingchatwoot.com
    official
  5. review
  6. review
  7. security
  8. security
  9. security
  10. security
  11. review
  12. review
  13. news
  14. news

Rate this review

Anonymous. You can change your vote.

Loading votes…

Comments

One queue. No nested comments. Give a display name first. Limit: 200 words per comment and 7 comments per day. You can edit or delete yours.

Save a name to write a comment.

0 / 200 words

No comments yet.