Should I use CometChat?
In-app Chat SDK & API for messaging and calling - cometchat.com
Depends. Buy if you're a dev team adding chat as a core feature of your app and can absorb per-MAU costs at scale. Skip if you want cheap plug-and-play chat or lack engineering resources to integrate and maintain SDKs.
Confidence
Medium. Based on 20+ public sources; many snippets truncated, so only confirmed figures are cited. No evidence names specific companies using competing services.
Ratings
- Value for money
- Ease of useNo clear third-party evidence
- Feature depth
- Support qualityReview base too thin to judge
- Security posture
Pricing
$0
Free
ModelNot disclosed
Monthly feesNot disclosed
HardwareNot disclosed
Free tierYes
Basic and paid tiersPer-MAU, scales with usage
CometChat Air (self-hosted)Custom / enterprise
Best for
- →Apps where chat is the core product
- →Marketplaces, dating, and community apps
- →Dev teams wanting chat, calling, and moderation in one SDK
- →Regulated teams needing self-hosted chat (CometChat Air)
Not for
- ×Solo founders needing a basic chat widget by Friday
- ×Non-technical teams — this is an SDK, not plug-and-play
- ×Anyone without budget headroom for per-MAU growth costs
- ×Apps where chat is a nice-to-have, not the product
Gotchas - check before you buy
high
Patch the JS SDK and UI kits promptly — a stored-XSS CVE was disclosed in 2026
medium
Costs scale per monthly active user; budget for spikes as your app grows
medium
Vendor-written competitor pricing comparisons favor CometChat; verify independently
low
Trustpilot review base is tiny; validate support quality during a trial
Pros and cons
Pros
- +Full-stack SDKs: chat, voice, moderation, AI agents in one platform
- +Full-featured free plan to start
- +Named G2 High Performer
- +Self-hosted enterprise option (CometChat Air) for data control
- +Named customers include NoBroker, Multiply, Twogo, SDVerse
Cons
- −Stored-XSS CVE (CVE-2026-39154) in its JS SDK
- −React UI kit flagged with high-severity vulnerability
- −Per-MAU pricing gets expensive as you scale
- −Employee reviews average 2.2/5 — company-health warning sign
Sources & method
Analyzed 9/26/2026 - 12 sources - Active vulnerability disclosure program and compliance efforts, but a 2026 stored-XSS CVE affected the JS SDK and a React UI kit was flagged high-severity.
official x4review x5security x2news x1
- CVE-2026-39154 — Stored XSS in CometChat JS SDK, Disclosed 2026; affects the CometChat JavaScript SDK.
- AIKIDO-2026-10360 — High vulnerability in @cometchat/chat-uikit-react, Affected versions flagged; users should upgrade the React UI kit.
- Legacy: multiple vulnerabilities (2013), Historical exploit-db listing against the old PHP product; unlikely to affect current SDKs.
Comments
One queue. No nested comments. Give a display name first. Limit: 200 words per comment and 7 comments per day. You can edit or delete yours.
No comments yet.