shouldiuse.io

VERDICT

Should I use H5P?

H5P is a platform that lets you create rich, responsive interactive content such as quizzes, videos, games and more - and embed it seamlessly into your LMS. - h5p.com

Depends. Buy if you are an educator or institution embedding interactive quizzes and video into Moodle, WordPress, or another LMS — the free self-hosted core is genuinely valuable. Skip it if you need fast corporate course authoring, webcam/screen capture, or a simple all-free tool.

Confidence

Medium. Based on 30+ public sources: reviews, Reddit threads, CVE databases, and official H5P pages. No aggregate star ratings or exact SaaS prices found in evidence.

Ratings

  • Value for money
  • Ease of use
  • Feature depth
  • Support qualityNo support evidence in sources reviewed
  • Security posture

Pricing

Free

Open-source plugin (h5p.org)

ModelNot disclosed
Monthly feesNot disclosed
HardwareNot disclosed
Free tierYes
H5P.com SaaSPaid plans (per user)

Best for

  • Educators in Moodle/WordPress LMSs
  • Universities and school districts
  • Budget-conscious instructional designers
  • Teams reusing open educational content

Not for

  • Corporate teams needing fast, polished SCORM course authoring
  • Anyone expecting itself to be free
  • Content requiring webcam or screen recording
  • Teams with no LMS to embed into

Gotchas - check before you buy

high

Self-hosters must patch promptly — WordPress plugin shipped arbitrary-file-deletion and stored-XSS bugs

medium

(free plugin) and (paid SaaS) are different products — Reddit threads are full of pricing confusion

medium

Moodle users note premium features require paying for alongside your LMS

medium

Hudson Rock flags as high threat posture with 9,976 infostealer credentials tied to the domain

Pros and cons

Pros

  • Rich interactive content — quizzes, videos, games — embeds directly into your LMS
  • Free, open-source core you can self-host in WordPress or Moodle
  • Used by over 100,000 organizations
  • Shared content hub for reusing other educators' material
  • Accessibility focus with published GDPR and DPA compliance

Cons

  • Authoring takes much longer than users expect
  • No webcam or screen recording support
  • Free-vs-paid split confuses buyers; is paid SaaS
  • Recurring stored-XSS and authorization CVEs in plugin ecosystem
  • Some content types carry accessibility issues

Sources & method

Analyzed 9/21/2026 - 12 sources - Recurring stored-XSS and authorization CVEs in the WordPress/Node ecosystem; the commercial SaaS publishes a compliance page and DPA.

official x2review x5security x3news x2
  • CVE-2025-7062 — Stored XSS in h5p-nodejs-library, Stored cross-site scripting vulnerability reported in the H5P library.
  • CVE-2024-3111 — Stored XSS in WordPress plugin, Contributor+ stored XSS in Interactive Content – H5P, fixed in 1.15.8.
  • Arbitrary file deletion — WordPress plugin ≤ 1.17.7, Authenticated contributor-level users could delete arbitrary files via the plugin.
  • CVE-2025-68505 — Missing authorization, Missing authorization vulnerability reported in the H5P plugin.

Key stats

  • Value for money: 4/5

    Rating

  • Free

    Starting price

  • 12

    Sources

  • Analyzed

  • Value for money: 4/5. Free open-source core; SaaS pricing opaque
  • Ease of use: 3/5. Easy start, but authoring is time-consuming
  • Feature depth: 4/5. Many content types; no webcam/screen capture
  • Support quality. No support evidence in sources reviewed
  • Security posture: 2/5. Repeated XSS and authorization CVEs
  • 100,000+ Organizations using it per Capterra, 2026
  • 17,000+ Websites per Wikipedia
  • Yes Free tier open-source core at h5p.org
  • $102.7K Projected annual spend H5P Group, per Crunchbase

Pricing

Open-source plugin (h5p.org)

Free

  • Self-host on WordPress, Moodle, Drupal
  • Community support

H5P.com SaaS

Paid plans (per user)

  • Hosted, with premium features and LMS integrations
  • Exact pricing not shown in sources reviewed

Security

Recurring stored-XSS and authorization CVEs in the WordPress/Node ecosystem; the commercial SaaS publishes a compliance page and DPA.

  • CVE-2025-7062 — Stored XSS in h5p-nodejs-libraryStored cross-site scripting vulnerability reported in the H5P library.
  • CVE-2024-3111 — Stored XSS in WordPress pluginContributor+ stored XSS in Interactive Content – H5P, fixed in 1.15.8.⁹
  • Arbitrary file deletion — WordPress plugin ≤ 1.17.7Authenticated contributor-level users could delete arbitrary files via the plugin.⁸
  • CVE-2025-68505 — Missing authorizationMissing authorization vulnerability reported in the H5P plugin.

What users say

Educators praise the interactive content range and LMS fit, but many complain authoring is slow and the free-vs-paid split is confusing.

“H5P is not versatile enough and offers no webcam or screen”
eLearning Industry review
“Creating content in H5P is a lot more time consuming than it”
Reddit, r/elearning
“My workplace (a university) recently bought H5P SaaS”
Reddit, r/instructionaldesign

Companies that use it

  • AISD
  • University of Texas Rio Grande Valley
  • Loughborough University
  • New York University (SPS)
  • UNC Greensboro
Full analysis

Based on 30+ public sources: reviews, Reddit threads, CVE databases, and official H5P pages. No aggregate star ratings or exact SaaS prices found in evidence.

Solid free/open interactive content for LMS users; SaaS pricing confuses and authoring is slow. Great for educators, not corporate speed.

Methodology

Based on 30+ public sources: reviews, Reddit threads, CVE databases, and official H5P pages. No aggregate star ratings or exact SaaS prices found in evidence.

Sources

  1. official
  2. official
  3. review
  4. review
  5. review
  6. review
  7. review
  8. security
  9. security
  10. security
  11. H5P — Wikipediaen.wikipedia.org
    news
  12. news

Rate this review

Anonymous. You can change your vote.

Loading votes…

Comments

One queue. No nested comments. Give a display name first. Limit: 200 words per comment and 7 comments per day. You can edit or delete yours.

Save a name to write a comment.

0 / 200 words

No comments yet.