shouldiuse.io

Categories

VERDICT

Should I use Hasura?

Not disclosed - hasura.io

Depends. Buy if you run Postgres and need instant, governed GraphQL with realtime and federation at real scale. Skip if you want a simple, cheap backend or predictable monthly bills.

Confidence

Medium. Based on ~40 public sources: G2 reviews, Reddit threads, CVE databases, case studies, and funding news.

Ratings

  • Value for money
  • Ease of use
  • Feature depth
  • Support qualityNo supporting evidence in sources
  • Security posture

Pricing

$0

Guess: Free (cloud)

ModelNot disclosed
Monthly feesNot disclosed
HardwareNot disclosed
Free tierYes
Guess: Usage-based cloudPay per usage
Enterprise / DDNCustom

Best for

  • Postgres-heavy products needing instant GraphQL
  • Realtime apps using subscriptions
  • Federating many data sources into one API (DDN)
  • Platform teams standardizing data access

Not for

  • Small CRUD apps — Supabase or PostgREST is cheaper and simpler
  • Teams wanting a predictable flat monthly bill
  • Non-GraphQL stacks hunting a basic REST BaaS
  • Teams that can't patch engine CVEs quickly

Gotchas - check before you buy

high

2023 pricing overhaul caused bill shock; community called it 'full bananas'

high

Deployed without auth, Hasura exposes your entire database publicly

medium

Legacy v2 plans being deprecated; migration churn toward DDN/PromptQL

medium

Hasura-specific permission metadata means real rework if you migrate away

Pros and cons

Pros

  • Instant GraphQL APIs and authorization on top of existing Postgres
  • Rated 4.7/5 on G2 across 26 reviews
  • Proven at scale with edge caching (RMRK)
  • Philips Healthcare reported 4x faster development
  • Users report stable production performance

Cons

  • Community revolted over the usage-based pricing revamp
  • Multiple CVEs including command injection and information disclosure
  • Fine-grained permissions are powerful but a security foot-gun
  • Hosting and billing options make total cost opaque

Sources & method

Analyzed 10/05/2026 - 12 sources - Multiple CVEs across versions; vendor discloses and patches, but auth misconfiguration remains the top real-world risk.

official x3review x5security x3news x1
  • CVE-2021-47748 — OS command injection in run_sql endpoint, RCE-class flaw in Hasura GraphQL engine's run_sql endpoint.
  • CVE-2023-27588 — unauthenticated path traversal, Unauthenticated path traversal vulnerability in the GraphQL engine.
  • CVE-2026-54698 — information disclosure, Information disclosure vulnerability in Hasura GraphQL.
  • Critical vulnerability in engine v2.10.0, Vendor-disclosed critical vulnerability and fix, November 2025.

Key stats

  • Value for money: 2/5

    Rating

  • $0

    Starting price

  • 12

    Sources

  • Analyzed

  • Value for money: 2/5. Usage-based pricing changes drew strong community backlash
  • Ease of use: 4/5. Instant APIs from existing Postgres
  • Feature depth: 4/5. Auth, subscriptions, caching, multi-source federation
  • Support quality. No supporting evidence in sources
  • Security posture: 2/5. Multiple CVEs including command injection and disclosure
  • 4.7/5 G2 rating 26 reviews
  • Yes Free tier cloud plan; paid usage tiers above it
  • $100M Series B Funding Feb 2022, $1B valuation
  • 4x Reported dev speedup Philips Healthcare case study

Pricing

Guess: Free (cloud)

$0

  • Core GraphQL engine
  • Usage limits apply

Guess: Usage-based cloud

Pay per usage

  • Scaling and caching
  • Billing tied to request volume

Enterprise / DDN

Not disclosed

  • SSO, SLAs
  • Private deployments

Security

Multiple CVEs across versions; vendor discloses and patches, but auth misconfiguration remains the top real-world risk.

  • CVE-2021-47748 — OS command injection in run_sql endpointRCE-class flaw in Hasura GraphQL engine's run_sql endpoint.⁹
  • CVE-2023-27588 — unauthenticated path traversalUnauthenticated path traversal vulnerability in the GraphQL engine.10
  • CVE-2026-54698 — information disclosureInformation disclosure vulnerability in Hasura GraphQL.11
  • Critical vulnerability in engine v2.10.0Vendor-disclosed critical vulnerability and fix, November 2025.

What users say

Reviewers praise the instant-API model and production stability but complain about pricing changes and permission complexity.

“We use Hasura in product”
Reddit, r/graphql
“Hasura is stable”
AWS Marketplace review
“Hasura's approach is dec”
Hacker News

Companies that use it

Full analysis

Based on ~40 public sources: G2 reviews, Reddit threads, CVE databases, case studies, and funding news.

Powerful instant GraphQL over Postgres — great at scale, but pricing surprises and CVE history demand mature ops.

Methodology

Based on ~40 public sources: G2 reviews, Reddit threads, CVE databases, case studies, and funding news.

Sources

  1. review
  2. review
  3. review
  4. review
  5. review
  6. Philips Healthcare case studygraphql-engine-cdn.hasura.io
    official
  7. Pipe case studygraphql-engine-cdn.hasura.io
    official
  8. official
  9. security
  10. security
  11. security
  12. news

Rate this review

Anonymous. You can change your vote.

Loading votes…

Comments

One queue. No nested comments. Give a display name first. Limit: 200 words per comment and 7 comments per day. You can edit or delete yours.

Save a name to write a comment.

0 / 200 words

No comments yet.