shouldiuse.io

Categories

VERDICT

Countly Review

Depends

Should I use Countly?

Privacy-first product analytics you can self-host - countly.com

· 1 day ago

Choose Countly if data control, self-hosting, or privacy compliance are real requirements and you have ops capacity or enterprise budget. If you are a small team or startup, free tiers of PostHog, Mixpanel, or simple web analytics will serve you better.

Confidence

Medium. Based on 17 public sources spanning reviews, security, pricing, and company data; many snippets were truncated, limiting specifics.

Ratings

  • Value for money
  • Ease of useReview snippets don't address usability
  • Feature depth
  • Support qualityNo support evidence in sources
  • Security posture

Pricing

Free

Open source (self-hosted)

ModelNot disclosed
Monthly feesNot disclosed
HardwareNot disclosed
Free tierYes
LiteNot published in sources
EnterpriseCustom

Best for

  • Mobile app teams needing deep event analytics
  • Companies that must self-host for data control
  • Privacy-sensitive or regulated markets (GDPR, DPDP)
  • Mid-size teams consolidating analytics

Not for

  • Seed-stage startups — free PostHog or GA4 covers the basics
  • Teams with no DevOps to run and patch servers
  • Simple sites wanting pageviews only — Plausible is lighter
  • Buyers wanting transparent, published pricing

Gotchas - check before you buy

medium

Self-hosting puts patching on you; the DBViewer bypass hit unpatched servers

medium

Cloud pricing beyond Lite isn't publicly listed; expect a sales conversation at scale

medium

104 credentials tied to appeared in infostealer logs; enforce dashboard 2FA

low

Third-party managed hosting exists for Countly — a signal self-hosting carries real ops burden

Pros and cons

Pros

  • Open-source core can be self-hosted, keeping raw data under your control
  • Privacy-first positioning with built-in GDPR and compliance tooling
  • Covers product, web, and mobile analytics in one platform
  • Only Countly offered a free tier in one head-to-head comparison
  • Rated 4-plus on G2 across roughly 20 reviews

Cons

  • DBViewer authorization bypass CVE (CVSS 7.1) disclosed September 2026
  • Unauthenticated path traversal in server fixed July 2026
  • Older CVE-2022-29174 suggests recurring server-side security issues
  • Small review base (~20 G2 reviews) next to bigger rivals

Sources & method

- 17 sources - Countly Server carries recent CVEs (2026 auth bypass, path traversal); privacy tooling is a strength but patching is critical.

official x1review x9security x5news x2
  • CVE-2026-87803 — DBViewer authorization bypass, Incorrect authorization in Countly Server DBViewer, CVSS 7.1, disclosed September 2026.
  • Unauthenticated path traversal via public image upload, GitHub advisory GHSA-fqgp-6rm9-8696, published July 2026.
  • CVE-2022-29174, Affects Countly Server version 22.03.

Key stats

  • Value for money: 4/5

    Rating

  • Free

    Starting price

  • 17

    Sources

  • Analyzed

  • Value for money: 4/5. Free self-hosted core; enterprise tiers cost more
  • Ease of use. Review snippets don't address usability
  • Feature depth: 4/5. Product, web, mobile analytics plus A/B testing, compliance
  • Support quality. No support evidence in sources
  • Security posture: 2/5. 2026 auth bypass and path traversal CVEs
  • 4+/5 G2 rating ~20 reviews
  • Yes Free tier Open-source, self-hosted core
  • 2011 Founded Bootstrapped, no VC funding
  • 7-figure ARR Scale Per 2026 founder interview

Pricing

Open source (self-hosted)

Free

  • Core analytics
  • You run hosting, upgrades, and security

Lite

Not published in sources

  • Entry cloud tier

Enterprise

Not disclosed

  • Compliance and privacy tooling
  • Contact-sales pricing

Security

Countly Server carries recent CVEs (2026 auth bypass, path traversal); privacy tooling is a strength but patching is critical.

  • CVE-2026-87803 — DBViewer authorization bypassIncorrect authorization in Countly Server DBViewer, CVSS 7.1, disclosed September 2026.10
  • Unauthenticated path traversal via public image uploadGitHub advisory GHSA-fqgp-6rm9-8696, published July 2026.12
  • CVE-2022-29174Affects Countly Server version 22.03.13

What users say

Reviewers rate Countly around 4 on G2 and praise it, but its review footprint is small versus PostHog, Mixpanel, and Amplitude.

“Countly is great tool to...”
G2 review
“"I would definitely reco...”
IrisVision customer, Countly case study

Companies that use it

  • IrisVision
  • Eventpedia
  • NedGraphics
Full analysis

Based on 17 public sources spanning reviews, security, pricing, and company data; many snippets were truncated, limiting specifics.

Privacy-first, self-hostable product analytics for serious teams; heavy for startups — PostHog or Plausible likely suffice.

Methodology

Based on 17 public sources spanning reviews, security, pricing, and company data; many snippets were truncated, limiting specifics.

Read how a report is made.

Sources

  1. review
  2. review
  3. review
  4. review
  5. review
  6. review
  7. review
  8. review
  9. review
  10. security
  11. security
  12. security
  13. security
  14. security
  15. official
  16. news
  17. news

Rate this review

Anonymous. You can change your vote.

Loading votes…

Comments

One queue. No nested comments. Give a display name first. Limit: 200 words per comment and 7 comments per day. You can edit or delete yours.

Save a name to write a comment.

0 / 200 words

No comments yet.