shouldiuse.io

Categories

VERDICT

Should I use Icinga?

Skip to consent choices - icinga.com

Depends. Buy it if you run a large, heterogeneous infrastructure and have sysadmins to configure and patch it. Small teams wanting simple monitoring should pick PRTG or Netdata instead.

Confidence

Medium. Based on 20+ public sources: reviews, Reddit threads, security advisories, and official pages. Pricing specifics thin; confidence medium.

Ratings

  • Value for money
  • Ease of use
  • Feature depth
  • Support qualityPaid SLAs exist but no reliable user evidence found
  • Security posture

Pricing

Free

Open Source

ModelNot disclosed
Monthly feesNot disclosed
HardwareNot disclosed
Free tierYes
Support subscriptionQuote-based
Repository OnlyQuote-based

Best for

  • Large heterogeneous server fleets
  • Nagios refugees wanting a modern fork
  • MSPs monitoring many client environments
  • Open-source shops with dedicated ops staff

Not for

  • Small teams without a dedicated sysadmin
  • Anyone wanting transparent, published pricing
  • Buyers needing quick, low-maintenance setup
  • Guess: Kubernetes-first teams wanting turnkey observability

Gotchas - check before you buy

high

Repository access moved behind paid subscriptions; some long-time users migrated away

high

Self-hosted installs mean you own patching; critical CVEs recurred 2024–2026

medium

Enterprise pricing is quote-based; buyers complain they can't get a straight answer online

medium

Vendor is small and unfunded; verify support SLA capacity before signing contracts

Pros and cons

Pros

  • Open-source core is free to self-host
  • Enterprise-grade and scales across large infrastructures
  • Sysadmins consider it more mature than Nagios
  • Purpose-built for MSPs monitoring multiple customer environments
  • Security team ships prompt, well-communicated patches

Cons

  • Setup documentation widely panned by users
  • Critical auth-bypass CVE in 2025 forced emergency patching
  • Tiny bootstrapped vendor (~$1.4M est. ARR) behind enterprise tooling
  • Shift to paid repository access drove users to alternatives

Sources & method

Analyzed 9/29/2026 - 14 sources - Actively patched, but repeated CVEs in 2024–2026, including a critical auth bypass (CVE-2025-48057).

official x2review x7security x4news x1
  • CVE-2025-48057 — Icinga 2 authentication bypass, Rated critical; Belgium's CCB urged immediate patching. Fixed in 2.14.6, 2.13.12 and 2.12.12 (May 2025).
  • CVE-2025-61908 — denial-of-service vulnerability in Icinga 2, DoS flaw tracked in public vulnerability databases; addressed in security releases 2.16.2, 2.15.4 and 2.14.9 (June 2026).
  • Path traversal vulnerabilities in Icinga Web, SonarSource researchers disclosed path traversal issues in Icinga Web 2 in 2022.

Key stats

  • Value for money: 3/5

    Rating

  • Free

    Starting price

  • 14

    Sources

  • Analyzed

  • Value for money: 3/5. Free core, but paid repos and quote-based support annoy users
  • Ease of use: 2/5. Setup documentation widely panned by users
  • Feature depth: 4/5. Enterprise-grade, scales, seen as more mature than Nagios
  • Support quality. Paid SLAs exist but no reliable user evidence found
  • Security posture: 2/5. Repeated CVEs 2024–2026, including critical auth bypass
  • 4.4/5 G2 rating 22 reviews across Icinga products
  • Yes Free tier Open-source core, self-hosted
  • 2018 Founded Icinga GmbH, Germany
  • None raised Funding ~$1.4M est. ARR

Pricing

Open Source

Free

  • Self-hosted monitoring core
  • Community support
  • Full Icinga 2 + Web

Support subscription

Quote-based

  • SLA-backed vendor support
  • Certified packages

Repository Only

Quote-based

  • Access to official package repositories

Security

Actively patched, but repeated CVEs in 2024–2026, including a critical auth bypass (CVE-2025-48057).

  • CVE-2025-48057 — Icinga 2 authentication bypassRated critical; Belgium's CCB urged immediate patching. Fixed in 2.14.6, 2.13.12 and 2.12.12 (May 2025).10
  • CVE-2025-61908 — denial-of-service vulnerability in Icinga 2DoS flaw tracked in public vulnerability databases; addressed in security releases 2.16.2, 2.15.4 and 2.14.9 (June 2026).12
  • Path traversal vulnerabilities in Icinga WebSonarSource researchers disclosed path traversal issues in Icinga Web 2 in 2022.11

Alternatives

Compare Icinga with each alternative.

  • Netdata

    Real-time monitoring with far easier setup; outranks Icinga on PeerSpot

  • PRTG

    Turnkey, sensor-based monitoring that suits small teams better

  • SigNoz

    Open-source observability pitched at cloud-native and Kubernetes teams

    Icinga vs SigNoz

Companies that use it

  • City of Cologne
  • Rohde & Schwarz
  • Magazine Luiza
Full analysis

Based on 20+ public sources: reviews, Reddit threads, security advisories, and official pages. Pricing specifics thin; confidence medium.

Enterprise-grade open-source monitoring; great for staffed ops teams, fiddly and overkill for small setups.

Methodology

Based on 20+ public sources: reviews, Reddit threads, security advisories, and official pages. Pricing specifics thin; confidence medium.

Sources

  1. review
  2. review
  3. review
  4. review
  5. review
  6. review
  7. review
  8. official
  9. security
  10. security
  11. security
  12. security
  13. Icinga Companyicinga.com
    official
  14. news

Rate this review

Anonymous. You can change your vote.

Loading votes…

Comments

One queue. No nested comments. Give a display name first. Limit: 200 words per comment and 7 comments per day. You can edit or delete yours.

Save a name to write a comment.

0 / 200 words

No comments yet.