shouldiuse.io

VERDICT

Should I use Filezilla-project?

The free FTP solution - filezilla-project.org

Worth it. Buy if you need a free, dependable FTP/SFTP client — it's the de facto standard with a huge user base. Skip it for enterprise managed file transfer, or if installer adware and weak password storage are dealbreakers; try WinSCP or Cyberduck instead.

Confidence

High. Based on 40+ public sources: Reddit threads, CVE databases, vendor pages, and review sites.

Ratings

  • Value for money
  • Ease of use
  • Feature depth
  • Support quality
  • Security posture

Pricing

Free

FileZilla Client

ModelNot disclosed
Monthly feesNot disclosed
HardwareNot disclosed
Free tierYes
FileZilla ProPaid — see vendor pricing page

Best for

  • Web developers uploading to servers
  • Sysadmins doing quick SFTP transfers
  • Anyone needing free cross-platform FTP
  • Students and hobbyists

Not for

  • Enterprises needing audited, managed file transfer
  • Non-technical users unwilling to dodge bundled-install offers
  • Teams whose cloud storage transfers belong in the free client
  • Compliance-heavy shops that must trust stored credentials

Gotchas - check before you buy

high

Fake lookalike sites distribute a malicious version that steals login credentials — download only from the official site

high

Don't save production credentials in Site Manager; weak stored-password history and credential-theft warnings

medium

Download-page installer bundles offers; decline them or use a clean build

medium

Cloud storage protocols require paid FileZilla Pro, not the free client

Pros and cons

Pros

  • Free, open-source client and server — no subscription
  • Called the most-used FTP client; documentation and help are everywhere
  • Cross-platform: Mac, Windows, Linux builds
  • Long-time users report it is very reliable
  • Project participates in a bug bounty program

Cons

  • Official installer may include bundled sponsored offers; adware complaints
  • Stored passwords were plaintext for years; protections came late
  • 14 CVEs on record, including DoS and untrusted-search-path bugs
  • No official support — community forum only
  • Frequently triggers antivirus warnings, confusing legitimate users

Sources & method

Analyzed 9/25/2026 - 12 sources - Long-lived open-source project: 14 CVEs on record, a history of weak stored-password protection, and an active fake-site malware campaign.

official x3review x5security x4
  • Fake FileZilla site distributes credential-stealing trojan, Malwarebytes documented a lookalike domain hosting a malicious download that steals login credentials.
  • Insecure key recovery in clients before 3.67.0, Tenable flags versions prior to 3.67.0; update promptly.
  • Weak stored-password protection, Years of tracked requests to encrypt stored passwords; master-password feature arrived late.
  • Historical CVEs including DoS and untrusted search path, CVE-2019-25683 (client DoS), CVE-2019-5429 (untrusted search path), Terrapin SSH degradation pre-3.66.4.

Key stats

  • Value for money: 5/5

    Rating

  • Free

    Starting price

  • 12

    Sources

  • Analyzed

  • Value for money: 5/5. Free and open source, no paywall
  • Ease of use: 4/5. Standard two-pane flow; endless tutorials exist
  • Feature depth: 3/5. Strong FTP/SFTP; cloud needs paid Pro
  • Support quality: 2/5. Community forum only, no official support
  • Security posture: 2/5. 14 CVEs, plaintext-password history, lookalike-site malware
  • Free Price Client and server are open source
  • 767 G2 reviews Reviews on FileZilla's G2 seller profile
  • 14 CVEs on record Tracked by OpenCVE for filezilla-project
  • Most-used Adoption Called the most-used FTP client in comparisons

Pricing

FileZilla Client

Free

  • FTP/SFTP client
  • Open source (GPL)
  • Mac, Windows, Linux

FileZilla Pro

Paid — see vendor pricing page

  • Cloud and NAS protocols
  • CLI and server options

Security

Long-lived open-source project: 14 CVEs on record, a history of weak stored-password protection, and an active fake-site malware campaign.

  • Fake FileZilla site distributes credential-stealing trojanMalwarebytes documented a lookalike domain hosting a malicious download that steals login credentials.⁸
  • Insecure key recovery in clients before 3.67.0Tenable flags versions prior to 3.67.0; update promptly.10
  • Weak stored-password protectionYears of tracked requests to encrypt stored passwords; master-password feature arrived late.11
  • Historical CVEs including DoS and untrusted search pathCVE-2019-25683 (client DoS), CVE-2019-5429 (untrusted search path), Terrapin SSH degradation pre-3.66.4.⁹

What users say

Users call FileZilla a reliable free workhorse but complain about installer adware, antivirus false positives, and password storage.

“Its very reliable for me”
DPReview forums
“Yes, FileZilla is safe t...”
Reddit, r/admincraft
“FileZilla now contains adware if you download from the ...”
Reddit, r/sysadmin

Companies that use it

  • University of Alberta
Full analysis

Based on 40+ public sources: Reddit threads, CVE databases, vendor pages, and review sites.

Free, reliable FTP/SFTP standard. Watch the adware-laden installer, fake download sites, and stored passwords.

Methodology

Based on 40+ public sources: Reddit threads, CVE databases, vendor pages, and review sites.

Sources

  1. official
  2. FileZilla Licensefilezilla-project.org
    official
  3. official
  4. review
  5. review
  6. review
  7. review
  8. security
  9. security
  10. security
  11. security
  12. review

Rate this review

Anonymous. You can change your vote.

Loading votes…

Comments

One queue. No nested comments. Give a display name first. Limit: 200 words per comment and 7 comments per day. You can edit or delete yours.

Save a name to write a comment.

0 / 200 words

No comments yet.