shouldiuse.io

VERDICT

Should I use iTextpdf?

The leading Java and C# PDF Library SDK to create, manipulate, edit and extract from PDF documents. - itextpdf.com

Depends. Buy if you're an enterprise Java/.NET team generating PDFs at scale — statements, invoices, signed documents — with a five-figure software budget. Skip it if you're a small team or startup: the AGPL license or ~$45k/yr commercial price is a trap; use Apache PDFBox or OpenPDF instead.

Confidence

Medium. Based on ~30 public sources: Vendr pricing data, NVD/SentinelOne/Snyk CVE records, GitHub, Reddit threads, and vendor case studies.

Ratings

  • Value for money
  • Ease of useNo usable evidence in sources
  • Feature depth
  • Support qualityNo usable evidence in sources
  • Security posture

Pricing

Free

AGPL open source

ModelNot disclosed
Monthly feesNot disclosed
HardwareNot disclosed
Free tierYes
Commercial license~$45,000/yr avg
Enterprise/volumeUp to ~$210,000/yr

Best for

  • Enterprise Java/.NET document pipelines
  • High-volume statements, invoices, reports
  • Digital signatures and PDF/A compliance
  • Academic and open-source projects

Not for

  • Small teams — $45k/yr average is absurd for a PDF library
  • Closed-source startups unwilling to pay — AGPL obligates you
  • Buyers who need transparent, published pricing
  • Anyone on deprecated iText 5 expecting new features

Gotchas - check before you buy

high

AGPL confusion is rampant — buyers discover licensing obligations after shipping.

medium

Contracts reportedly range from ~$45k average to ~$210k/yr — huge spread, negotiate hard.

medium

Old iText 5 repo is deprecated; moving to iText 7/9 means API rework.

medium

Users report vulnerability warnings persisting even after upgrading iText 5.

Pros and cons

Pros

  • Deep toolkit: create, edit, HTML-to-PDF, data extraction, digital signing
  • 25-year track record, proven at banks and fintechs
  • Free under AGPL for open-source and academic work
  • Vendor is ISO/IEC 27001:2017 certified

Cons

  • Commercial licenses average $45,000/year, up to $210,000
  • No published pricing; sales call required
  • AGPL forces open-sourcing closed-source apps or paying
  • Legacy itextpdf repo deprecated, with known security issues
  • Multiple CVEs including a 2021 critical RCE

Sources & method

Analyzed 9/19/2026 - 11 sources - 7+ CVEs including a critical 2021 RCE; vendor is ISO 27001 certified and publishes CVE advisories.

official x3review x4security x3news x1
  • CVE-2021-43113 — Remote Code Execution, Critical command-injection/RCE vulnerability in iTextPDF.
  • CVE-2022-24196 — Denial of Service, DoS vulnerability in iText.
  • CVE-2022-24197 — Denial of Service, DoS in the:io package.
  • CVE-2017-9096 — XXE Attack, XXE vulnerability in the iText PDF parser affecting versions before 7.0.3.
  • CVE-2023-6299, Vulnerability classified as problematic by NIST.

Key stats

  • Value for money: 2/5

    Rating

  • Free

    Starting price

  • 11

    Sources

  • Analyzed

  • Value for money: 2/5. $45k/yr average; opaque contact-sales pricing
  • Ease of use. No usable evidence in sources
  • Feature depth: 5/5. Full toolkit: create, convert, sign, extract, PDF/A
  • Support quality. No usable evidence in sources
  • Security posture: 2/5. 7 CVEs incl. critical RCE; ISO 27001 certified
  • $45,000/yr Avg commercial license Contracts up to ~$210,000 (Vendr data)
  • Yes (AGPL) Free tier Only if you open-source your app
  • 7+ Public CVEs Incl. 2021 critical RCE
  • 25 years Track record Library launched ~2000

Pricing

AGPL open source

Free

  • Full core library
  • Must open-source your application
  • Community support

Commercial license

~$45,000/yr avg

  • Closed-source use allowed
  • Volume-based pricing
  • Contact sales — prices unpublished

Enterprise/volume

Up to ~$210,000/yr

  • High-volume deployments
  • Negotiated contract

Security

7+ CVEs including a critical 2021 RCE; vendor is ISO 27001 certified and publishes CVE advisories.

  • CVE-2021-43113 — Remote Code ExecutionCritical command-injection/RCE vulnerability in iTextPDF.³
  • CVE-2022-24196 — Denial of ServiceDoS vulnerability in iText.
  • CVE-2022-24197 — Denial of ServiceDoS in the:io package.⁴
  • CVE-2017-9096 — XXE AttackXXE vulnerability in the iText PDF parser affecting versions before 7.0.3.
  • CVE-2023-6299Vulnerability classified as problematic by NIST.⁵

What users say

Developers respect iText's power for Java PDF work but constantly flag AGPL licensing confusion and steep commercial pricing.

“iTextPDF is a wonderful option for free and academic projects.”
IronPDF vs iText comparison review
“Itext uses the agpl https://itextpdf.com/how-buy/AGPLv3-license.”
Reddit, r/java
“The site doesn't list any commercial licence prices.”
CodeRanch forum

Companies that use it

  • Green Dot Bank10
  • PayNearby
  • Capgemini
  • Swisscom Trust Services
  • SingPass
Full analysis

Based on ~30 public sources: Vendr pricing data, NVD/SentinelOne/Snyk CVE records, GitHub, Reddit threads, and vendor case studies.

Powerful enterprise PDF SDK for Java/.NET — but AGPL strings and ~$45k/yr licenses make it overkill for small projects.

Methodology

Based on ~30 public sources: Vendr pricing data, NVD/SentinelOne/Snyk CVE records, GitHub, Reddit threads, and vendor case studies.

Sources

  1. official
  2. review
  3. security
  4. security
  5. security
  6. official
  7. review
  8. review
  9. review
  10. official
  11. news

Rate this review

Anonymous. You can change your vote.

Loading votes…

Comments

One queue. No nested comments. Give a display name first. Limit: 200 words per comment and 7 comments per day. You can edit or delete yours.

Save a name to write a comment.

0 / 200 words

No comments yet.