shouldiuse.io

Categories

VERDICT

DataRecce (Recce) Review

Depends

Should I use DataRecce (Recce)?

The data-validation toolkit for enhanced dbt - datarecce.io

· 2 days ago

Buy if your team runs dbt and wants data impact checks inside pull requests — the open-source core is free and purpose-built for it. Skip it if you're not on dbt, want managed SaaS, or can't securely self-host; the OSS server has two published CVEs.

Confidence

Medium. Based on ~20 public sources; no independent customer reviews found. Pricing evidence was thin.

Ratings

  • Value for money
  • Ease of useNo independent user evidence
  • Feature depth
  • Support qualityNo support evidence found
  • Security posture

Pricing

Free

Recce OSS

ModelNot disclosed
Monthly feesNot disclosed
HardwareNot disclosed
Free tierYes
TeamNot published

Best for

  • dbt analytics engineering teams
  • PR-based data change review
  • Prod vs dev data diffing
  • Open-source-first shops

Not for

  • Non-dbt data stacks — value drops to near zero
  • Buyers wanting turnkey managed SaaS
  • Teams that can't patch self-hosted servers quickly
  • Business users wanting no-code data quality dashboards

Gotchas - check before you buy

high

Never expose the Recce server unauthenticated — high-severity unauthenticated SQL execution disclosed May 2026.

high

Run v1.50.0 or later; earlier versions ship the path traversal flaw CVE-2026-49360.

medium

No published pricing; paid team features exist but require contacting the vendor.

medium

Pre-seed-stage startup ($4M); long-term support and roadmap are unproven.

Pros and cons

Pros

  • Open-source data-validation toolkit built for dbt
  • Impact assessment before merging dbt changes
  • Adds data checks to PR review, cutting manual re-checking
  • AI-assisted validation via Claude plugin and MCP support
  • Backed by $4M pre-seed from Heavybit

Cons

  • dbt-specific; minimal value outside dbt projects
  • OSS server had unauthenticated SQL execution flaw (high severity)
  • Path traversal CVE-2026-49360, CVSS 7.8, before v1.50.0
  • Small ecosystem: ~482 GitHub stars limits community support
  • Pricing opaque; a 'Team' premium tier exists with no public price

Sources & method

- 10 sources - Two CVEs (2026) affecting the OSS server; patch to v1.50.0+ and never expose the server unauthenticated.

official x4review x2security x2news x2
  • Unauthenticated SQL execution (GHSA-rh62-j648-g5qc), High-severity flaw in Recce OSS server deployments exposed to the network; disclosed via GitHub advisory in May 2026.
  • CVE-2026-49360 — path traversal, CVSS 7.8; affects the OSS server prior to version 1.50.0.

Key stats

  • Value for money: 5/5

    Rating

  • Free

    Starting price

  • 10

    Sources

  • Analyzed

  • Value for money: 5/5. Free open-source core for dbt validation
  • Ease of use. No independent user evidence
  • Feature depth: 4/5. Diffs, lineage, impact checks, AI plugin
  • Support quality. No support evidence found
  • Security posture: 2/5. Two CVEs, including unauthenticated SQL execution
  • 482 GitHub stars small but focused community
  • $4M Funding pre-seed, backed by Heavybit
  • Yes Free tier Apache-2.0 licensed open-source core
  • 2 Known CVEs incl. CVE-2026-49360, CVSS 7.8

Pricing

Recce OSS

Free

  • Apache-2.0 licensed
  • Self-hosted
  • dbt validation toolkit

Team

Not published

  • Premium tier exists
  • Contact vendor for price

Security

Two CVEs (2026) affecting the OSS server; patch to v1.50.0+ and never expose the server unauthenticated.

  • Unauthenticated SQL execution (GHSA-rh62-j648-g5qc)High-severity flaw in Recce OSS server deployments exposed to the network; disclosed via GitHub advisory in May 2026.³
  • CVE-2026-49360 — path traversalCVSS 7.8; affects the OSS server prior to version 1.50.0.⁴

What users say

No independent user reviews found; content is mostly company-published, with one third-party GitHub issue asking whether anyone uses the tool.

Full analysis

Based on ~20 public sources; no independent customer reviews found. Pricing evidence was thin.

Free OSS dbt diff & impact-check tool for PR reviews. No dbt, no point. Self-host carefully — 2 CVEs on record.

Methodology

Based on ~20 public sources; no independent customer reviews found. Pricing evidence was thin.

Read how a report is made.

Sources

  1. official
  2. official
  3. security
  4. CVE-2026-49360 detailscyber-defence.io
    security
  5. news
  6. news
  7. official
  8. review
  9. review
  10. official

Rate this review

Anonymous. You can change your vote.

Loading votes…

Comments

One queue. No nested comments. Give a display name first. Limit: 200 words per comment and 7 comments per day. You can edit or delete yours.

Save a name to write a comment.

0 / 200 words

No comments yet.