shouldiuse.io

VERDICT

Should I use Immich?

Self-hosted photo and video management solution. Easily back up, organize, and manage your photos on your own server. - immich.app

Depends. Buy it if you already run a home server and want Google Photos features without Google. Skip it if you won't personally maintain, back up, and secure that server.

Confidence

Medium. Based on ~40 public sources: Reddit threads, security advisories, official docs and blog, pricing pages, and comparison reviews.

Ratings

  • Value for money
  • Ease of use
  • Feature depth
  • Support quality
  • Security posture

Pricing

$0

Self-hosted

ModelNot disclosed
Monthly feesNot disclosed
HardwareNot disclosed
Free tierYes
Immich licensePaid, per server or per user
Managed hosting (Elestio)Monthly, varies by plan

Best for

  • Homelabbers comfortable with Docker
  • Privacy-focused families leaving Google Photos
  • Photo hoarders with local storage
  • Self-hosting communities and resellers

Not for

  • Non-technical users without a server
  • Anyone wanting zero-maintenance backup
  • Buyers needing vendor SLAs or support contracts
  • Families who resent fiddling with permissions

Gotchas - check before you buy

high

Exposing Immich to the internet without VPN or firewall is the top attack vector users get burned on

high

You own backups. Immich stores your only photo copy — no server backup means total loss

medium

Major version upgrades can break installs; snapshot your stack before updating

low

Paid product keys arrived in 2024; unpaid self-hosting still allowed, but verify terms before assuming free forever

Pros and cons

Pros

  • Free to self-host; optional paid license funds development
  • Native mobile apps with automatic backup, unlike PhotoPrism
  • Huge community: 80,000+ GitHub stars, active forums
  • Full-time core team, FUTO-funded, no VC pressure
  • Some users report it surpassed Google Photos for their needs

Cons

  • Self-hosting demands Docker skills, storage planning, ongoing maintenance
  • Sharing with family is clunky and permission-heavy
  • Several 2025–2026 CVEs: auth bypass, XSS, privilege escalation
  • Remote access needs careful hardening or you're exposed
  • Breaking upgrades happen; rollbacks require care

Sources & method

Analyzed 9/21/2026 - 12 sources - Multiple CVEs disclosed in 2025–2026 (auth bypass, XSS, privilege escalation, OAuth account hijacking); keep patched and limit internet exposure.

official x3review x5security x3news x1
  • CVE-2026-59258: Auth bypass, Authentication bypass vulnerability disclosed via SentinelOne's vulnerability database.
  • CVE-2026-40096: XSS, Cross-site scripting vulnerability in Immich, tracked by SentinelOne and NVD.
  • CVE-2026-23896: Privilege escalation, Escalation vulnerability allowing unauthorized privilege gain once foothold exists.
  • GHSA-3832-6r8h-9cfm: OAuth2 account hijacking, Official advisory covering account hijacking through OAuth2 flows.
  • Critical Redis container vulnerability, Widely discussed Redis dependency flaw affecting Immich deployments.

Key stats

  • Value for money: 5/5

    Rating

  • $0

    Starting price

  • 12

    Sources

  • Analyzed

  • Value for money: 5/5. Free self-hosted; paid keys optional
  • Ease of use: 2/5. Docker/server skills required; family setup friction
  • Feature depth: 4/5. Native mobile apps, ML search, multi-user
  • Support quality: 3/5. Community-driven; managed hosting via Elestio exists
  • Security posture: 2/5. Multiple 2025–2026 CVEs disclosed
  • $0 Starting price Free self-hosted; paid license optional
  • Yes Free tier Unpaid self-hosting remains allowed
  • 80,000+ GitHub stars Per LinuxBlog.io, Oct 2025
  • FUTO-backed Funding 3-year commitment, no VC

Pricing

Self-hosted

$0

  • Full feature set
  • Optional paid product key

Immich license

Paid, per server or per user

  • One-time purchase via buy.immich.app
  • Supports development

Managed hosting (Elestio)

Monthly, varies by plan

  • Hosted for you
  • No server skills needed

Security

Multiple CVEs disclosed in 2025–2026 (auth bypass, XSS, privilege escalation, OAuth account hijacking); keep patched and limit internet exposure.

  • CVE-2026-59258: Auth bypassAuthentication bypass vulnerability disclosed via SentinelOne's vulnerability database.10
  • CVE-2026-40096: XSSCross-site scripting vulnerability in Immich, tracked by SentinelOne and NVD.
  • CVE-2026-23896: Privilege escalationEscalation vulnerability allowing unauthorized privilege gain once foothold exists.
  • GHSA-3832-6r8h-9cfm: OAuth2 account hijackingOfficial advisory covering account hijacking through OAuth2 flows.11
  • Critical Redis container vulnerabilityWidely discussed Redis dependency flaw affecting Immich deployments.

What users say

Self-hosters love it once running, but report setup friction, family-sharing headaches, and occasional reliability doubts.

“And just like that Immich already surpassed Google Photos for me!”
Reddit, r/selfhosted
“Immich is great… until you try using it with family”
Reddit, r/immich
“Immich great...until it isn't”
Reddit, r/selfhosted
Full analysis

Based on ~40 public sources: Reddit threads, security advisories, official docs and blog, pricing pages, and comparison reviews.

Free, powerful Google Photos replacement — if you'll run and secure a server yourself. Everyone else: pick a managed alternative.

Methodology

Based on ~40 public sources: Reddit threads, security advisories, official docs and blog, pricing pages, and comparison reviews.

Sources

  1. official
  2. Immich purchase pagebuy.immich.app
    official
  3. official
  4. news
  5. review
  6. review
  7. review
  8. review
  9. review
  10. security
  11. security
  12. security

Rate this review

Anonymous. You can change your vote.

Loading votes…

Comments

One queue. No nested comments. Give a display name first. Limit: 200 words per comment and 7 comments per day. You can edit or delete yours.

Save a name to write a comment.

0 / 200 words

No comments yet.