shouldiuse.io

Categories

VERDICT

Envato Review

Depends

Should I use Envato?

Create and customize content with AI tools and unlimited creative assets for professional and commercial use. - envato.com

· 2 weeks ago

Buy if you create content constantly and will actually use unlimited downloads at ~$16/mo. Skip if you need a handful of assets occasionally or expect premium quality and strong support.

Confidence

Medium. Based on ~20 public sources: G2, Trustpilot, Reddit, YouTube reviews, CVE databases, BBB, and official Envato pages.

Ratings

  • Value for money
  • Ease of useInsufficient evidence
  • Feature depth
  • Support quality
  • Security posture

Pricing

from ~US$16/mo

Core

ModelNot disclosed
Monthly feesNot disclosed
HardwareNot disclosed
Higher individual/team plansup to $109/mo on annual billing

Best for

  • Freelance designers and video editors
  • YouTubers and content creators
  • Agencies with constant content output
  • Anyone needing varied assets cheap

Not for

  • Occasional buyers who need one or two assets
  • Teams expecting consistent premium quality
  • Anyone needing fast, reliable customer support
  • Enterprises needing a hardened vendor security posture

Gotchas - check before you buy

high

Refund and billing complaints appear on Trustpilot and BBB

medium

Subscription only pays off with heavy monthly downloads; occasional users overpay

medium

Video editors report license-term confusion around commercial use

medium

Best pricing requires annual billing commitments, locking you in

Pros and cons

Pros

  • Unlimited downloads across video, music, graphics, templates, plus AI tools
  • Entry price around $16/mo is cheap for heavy users
  • G2 rated 4.1/5 by 240 reviewers
  • Some professional designers rely on it daily

Cons

  • Quality varies; some reviewed products called terrible
  • Trustpilot reviewers mostly unhappy across 155 reviews
  • Companion WordPress plugins have had multiple CVEs
  • 2025 breach claims of 11M emails; Envato found no evidence
  • Marketplace authors report forced removals and platform churn

Sources & method

- 9 sources - No confirmed breach of Envato's core platform; third-party WordPress plugins tied to Envato had CVEs; 2025 breach claims investigated with no evidence found.

official x2review x3security x2news x2
  • CVE-2024-56275: SSRF in WordPress Envato Elements plugin, Server-side request forgery affecting the Envato Elements WordPress plugin.
  • CVE-2025-32566: Reflected XSS in License For Envato plugin, Reflected cross-site scripting in a WordPress plugin for Envato licenses.
  • CVE-2025-62755: Missing authorization vulnerability, Missing authorization flaw recorded December 2025.
  • 2016 Tuts+ hack, Envato's Tuts+ site was hacked; emails and plaintext passwords exposed.
  • 2025 breach claims (~11M emails), Claims of 11M stolen emails circulated; Envato said no evidence of breach so far.

Key stats

  • Value for money: 4/5

    Rating

  • from ~US$16/mo

    Starting price

  • 9

    Sources

  • Analyzed

  • Value for money: 4/5. Unlimited downloads cheap for heavy users
  • Ease of use. Insufficient evidence
  • Feature depth: 4/5. Huge multi-category library plus AI tools
  • Support quality: 2/5. Trustpilot and BBB complaint volume
  • Security posture: 3/5. HackerOne program; plugin CVEs; breach claims probed
  • 4.1/5 G2 rating 240 reviews
  • ~US$16/mo Starting price Core plan; $16.50-$109/mo annual range
  • $198M ARR Est. revenue 2024 estimate
  • $373M Acquired for By Shutterstock, 2024

Pricing

Core

from ~US$16/mo

  • Unlimited downloads
  • AI tools
  • Commercial license

Higher individual/team plans

up to $109/mo on annual billing

  • More seats
  • Broader catalog access

Security

No confirmed breach of Envato's core platform; third-party WordPress plugins tied to Envato had CVEs; 2025 breach claims investigated with no evidence found.

  • CVE-2024-56275: SSRF in WordPress Envato Elements pluginServer-side request forgery affecting the Envato Elements WordPress plugin.⁷
  • CVE-2025-32566: Reflected XSS in License For Envato pluginReflected cross-site scripting in a WordPress plugin for Envato licenses.
  • CVE-2025-62755: Missing authorization vulnerabilityMissing authorization flaw recorded December 2025.
  • 2016 Tuts+ hackEnvato's Tuts+ site was hacked; emails and plaintext passwords exposed.
  • 2025 breach claims (~11M emails)Claims of 11M stolen emails circulated; Envato said no evidence of breach so far.⁶

Companies that use it

  • Loyola University Chicago
Full analysis

Based on ~20 public sources: G2, Trustpilot, Reddit, YouTube reviews, CVE databases, BBB, and official Envato pages.

Great-value unlimited asset firehose for daily creators; overkill for occasional buyers, with patchy support and quality variance.

Methodology

Based on ~20 public sources: G2, Trustpilot, Reddit, YouTube reviews, CVE databases, BBB, and official Envato pages.

Read how a report is made.

Sources

  1. review
  2. review
  3. official
  4. official
  5. review
  6. security
  7. security
  8. news
  9. news

Rate this review

Anonymous. You can change your vote.

Loading votes…

Comments

One queue. No nested comments. Give a display name first. Limit: 200 words per comment and 7 comments per day. You can edit or delete yours.

Save a name to write a comment.

0 / 200 words

No comments yet.