Should I use Immich?
Self-hosted photo and video management solution. Easily back up, organize, and manage your photos on your own server. - immich.app
Depends. Buy it if you already run a home server and want Google Photos features without Google. Skip it if you won't personally maintain, back up, and secure that server.
Confidence
Medium. Based on ~40 public sources: Reddit threads, security advisories, official docs and blog, pricing pages, and comparison reviews.
Ratings
- Value for money
- Ease of use
- Feature depth
- Support quality
- Security posture
Pricing
$0
Self-hosted
ModelNot disclosed
Monthly feesNot disclosed
HardwareNot disclosed
Free tierYes
Immich licensePaid, per server or per user
Managed hosting (Elestio)Monthly, varies by plan
Best for
- →Homelabbers comfortable with Docker
- →Privacy-focused families leaving Google Photos
- →Photo hoarders with local storage
- →Self-hosting communities and resellers
Not for
- ×Non-technical users without a server
- ×Anyone wanting zero-maintenance backup
- ×Buyers needing vendor SLAs or support contracts
- ×Families who resent fiddling with permissions
Gotchas - check before you buy
high
Exposing Immich to the internet without VPN or firewall is the top attack vector users get burned on
high
You own backups. Immich stores your only photo copy — no server backup means total loss
medium
Major version upgrades can break installs; snapshot your stack before updating
low
Paid product keys arrived in 2024; unpaid self-hosting still allowed, but verify terms before assuming free forever
Pros and cons
Pros
- +Free to self-host; optional paid license funds development
- +Native mobile apps with automatic backup, unlike PhotoPrism
- +Huge community: 80,000+ GitHub stars, active forums
- +Full-time core team, FUTO-funded, no VC pressure
- +Some users report it surpassed Google Photos for their needs
Cons
- −Self-hosting demands Docker skills, storage planning, ongoing maintenance
- −Sharing with family is clunky and permission-heavy
- −Several 2025–2026 CVEs: auth bypass, XSS, privilege escalation
- −Remote access needs careful hardening or you're exposed
- −Breaking upgrades happen; rollbacks require care
Sources & method
Analyzed 9/21/2026 - 12 sources - Multiple CVEs disclosed in 2025–2026 (auth bypass, XSS, privilege escalation, OAuth account hijacking); keep patched and limit internet exposure.
official x3review x5security x3news x1
- CVE-2026-59258: Auth bypass, Authentication bypass vulnerability disclosed via SentinelOne's vulnerability database.
- CVE-2026-40096: XSS, Cross-site scripting vulnerability in Immich, tracked by SentinelOne and NVD.
- CVE-2026-23896: Privilege escalation, Escalation vulnerability allowing unauthorized privilege gain once foothold exists.
- GHSA-3832-6r8h-9cfm: OAuth2 account hijacking, Official advisory covering account hijacking through OAuth2 flows.
- Critical Redis container vulnerability, Widely discussed Redis dependency flaw affecting Immich deployments.
Comments
One queue. No nested comments. Give a display name first. Limit: 200 words per comment and 7 comments per day. You can edit or delete yours.
No comments yet.