shouldiuse.io

Categories

VERDICT

Should I use HaloITSM?

Intuitive ITSM software for your Service Desk. Standardise your processes with a single, all-inclusive, unlimited IT service desk solution. Try for free! - haloitsm.com

Depends. Buy if you run a mid-size or larger IT desk or MSP and want one all-inclusive per-agent platform — it runs desks at Sky TV and Wiltshire Police. Skip it for small-team ticketing, and confirm your version is patched given the 2024–25 CVE run.

Confidence

Medium. Based on ~60 public sources; many snippets truncated, so no verbatim user quotes could be extracted.

Ratings

  • Value for money
  • Ease of useNo usable evidence in sources
  • Feature depth
  • Support qualityMixed, truncated signals only
  • Security posture

Pricing

Per-agent subscription

Quote-based; rates not published

ModelPer agent
Monthly feesNot disclosed
HardwareNot disclosed

Best for

  • Mid-size to large IT service desks
  • MSPs consolidating tooling
  • ITIL process standardization
  • Desk plus asset management in one platform

Not for

  • Small teams that just need a simple shared ticket list
  • Solo admins — a full ITSM suite is heavy overkill
  • Orgs that can't patch promptly given the CVE history
  • Buyers who need transparent published pricing

Gotchas - check before you buy

high

Several 2024–25 CVEs, including a CVSS 9.8 auth bypass — verify patch level before signing.

high

Pre-auth SQL injection disclosed April 2025 exposed orgs to remote hacking; affected versions up to 2.146.1.

medium

Per-agent pricing grows with headcount; quote-only rates make budgeting hard.

medium

Halo platform users report monthly invoicing is painful to configure.

Pros and cons

Pros

  • All-inclusive, unlimited ITSM suite covering desk, assets, workflows
  • Per-agent licensing model
  • Described as easily scalable across TrustRadius comparisons
  • Enterprise deployments at Sky TV, Natural History Museum, Wiltshire Police
  • MSPs are switching to it quickly, per migration write-ups

Cons

  • CVSS 9.8 authorization flaw (CVE-2024-6202)
  • Pre-auth SQL injection exposed organizations to remote hacking (2025)
  • Open redirect vulnerability (CVE-2025-40846)
  • Modest 3.8/5 average across 333 listed reviews
  • Monthly invoicing workflows reported as near-impossible on Halo platform

Sources & method

Analyzed 10/06/2026 - 12 sources - Multiple critical CVEs in 2024–2025, including a CVSS 9.8 authorization flaw and pre-auth SQL injection — patch level matters.

official x2review x6security x3news x1
  • CVE-2024-6202 — Incorrect Authorization (CVSS 9.8), Critical authorization vulnerability affecting HaloITSM versions up to 2.146.1.
  • Pre-auth SQL injection (2025), Assetnote found pre-authentication SQL injection that exposed organizations to remote hacking.
  • CVE-2024-6203, Affects HaloITSM versions up to 2.146.1.
  • CVE-2025-40846 — Open redirect, Open redirect vulnerability in HaloITSM.

Key stats

  • Value for money: 4/5

    Rating

  • Quote-based; rates not published

    Starting price

  • 12

    Sources

  • Analyzed

  • Value for money: 4/5. Per-agent model; MSPs migrating to it for cost
  • Ease of use. No usable evidence in sources
  • Feature depth: 4/5. All-inclusive ITIL suite; large multi-department deployments
  • Support quality. Mixed, truncated signals only
  • Security posture: 2/5. CVSS 9.8 flaw; pre-auth SQLi in 2025
  • 3.8/5 Rating 333 reviews (RFP.wiki)
  • Per agent Pricing model Quote-based, rates not published
  • #23 PeerSpot rank IT service management category
  • Yes Free trial "Try for free" on homepage

Pricing

Per-agent subscription

Quote-based; rates not published

  • All-inclusive unlimited ITSM modules
  • Billed per agent

Security

Multiple critical CVEs in 2024–2025, including a CVSS 9.8 authorization flaw and pre-auth SQL injection — patch level matters.

  • CVE-2024-6202 — Incorrect Authorization (CVSS 9.8)Critical authorization vulnerability affecting HaloITSM versions up to 2.146.1.⁹
  • Pre-auth SQL injection (2025)Assetnote found pre-authentication SQL injection that exposed organizations to remote hacking.⁸
  • CVE-2024-6203Affects HaloITSM versions up to 2.146.1.10
  • CVE-2025-40846 — Open redirectOpen redirect vulnerability in HaloITSM.

What users say

Comparisons pit it against Freshservice and Jira Service Management, with scalability praised and Halo-platform subreddits noting billing friction.

Alternatives

Compare HaloITSM with each alternative.

  • Freshservice

    Frequent head-to-head rival for mid-market ITSM

  • Jira Service Management

    Better fit if teams already live in Atlassian

  • SysAid

    Direct alternative marketed against HaloITSM

    HaloITSM vs SysAid

Companies that use it

  • Sky TV12
  • Natural History Museum
  • Wiltshire Police
  • TSG
  • Cambridge Helpdesk
Full analysis

Based on ~60 public sources; many snippets truncated, so no verbatim user quotes could be extracted.

All-in-one ITSM that scales for mid/large desks and MSPs; overkill for small teams. Check CVE history first.

Methodology

Based on ~60 public sources; many snippets truncated, so no verbatim user quotes could be extracted.

Sources

  1. official
  2. review
  3. review
  4. review
  5. review
  6. review
  7. review
  8. security
  9. security
  10. security
  11. news
  12. official

Rate this review

Anonymous. You can change your vote.

Loading votes…

Comments

One queue. No nested comments. Give a display name first. Limit: 200 words per comment and 7 comments per day. You can edit or delete yours.

Save a name to write a comment.

0 / 200 words

No comments yet.