shouldiuse.io

VERDICT

Should I use Jetpack CRM?

Simple, Easy to Use CRM for WordPress - jetpackcrm.com

Depends. Buy it if your small business already runs on WordPress and your sales process is simple. Skip it if you need a standalone CRM, deeper enterprise features, or can't patch plugins quickly.

Confidence

Medium. Based on 20+ public sources: Reddit threads, WordPress.org, security databases, and third-party reviews. Named-company user lists absent from evidence.

Ratings

  • Value for money
  • Ease of use
  • Feature depth
  • Support quality
  • Security posture

Pricing

$0

Free

ModelNot disclosed
Monthly feesNot disclosed
HardwareNot disclosed
Free tierYes
All Extensions$17/mo
Full Bundle$199/yr

Best for

  • Freelancers and micro-businesses
  • Existing WordPress + WooCommerce sites
  • Simple contact, quote, and invoice tracking
  • Budget-conscious lead tracking

Not for

  • Anyone without a WordPress site — it's a plugin, not standalone software
  • Larger sales teams needing permissions, forecasting, or compliance-grade controls
  • Teams unwilling to patch plugins immediately — unauthenticated attack CVEs exist
  • Buyers wanting a standalone CRM with independent hosting and backups handled for them

Gotchas - check before you buy

high

Unauthenticated file-inclusion and code-execution CVEs through v6.7.0; slow patching exposes your whole site.

medium

Free tier excludes extensions; realistic cost is $17/month or $199/year.

medium

CRM data lives on your own host — backups, uptime, and security are your job.

low

Best support reviews appear on the vendor's own site; independent feedback is thin.

Pros and cons

Pros

  • Free core covers contacts, funnels, and invoicing
  • All extensions for $17/month; cheaper than SaaS CRMs
  • No-fuss CRM that lives inside WordPress
  • Tight WooCommerce integration for tracking and retargeting
  • Backed by Automattic, the company behind WordPress

Cons

  • Repeated high-severity CVEs, some unauthenticated
  • Feature set is basic; users cite modest needs only
  • Requires a WordPress site; not usable standalone
  • Primarily a sales CRM; marketing depth is limited
  • Small independent review base: 152 ratings

Sources & method

Analyzed 9/21/2026 - 12 sources - Multiple CVEs (2022–2026), including unauthenticated local file inclusion; patching discipline required.

official x3review x5security x4
  • CVE-2026-22356: PHP local file inclusion, Path traversal flaw enabling PHP local file inclusion in Automattic Jetpack CRM through version 6.7.0.
  • Unauthenticated LFI, fixed in 6.7.1, Unauthenticated attackers can include and execute arbitrary files on the server in versions below 6.7.1.
  • Stored XSS in 5.4.2 and below, Authenticated administrator stored cross-site scripting via plugin settings.
  • CVE-2022-3342: unauthenticated code execution, Code execution reachable without authentication; patched in core 4.2.4.

Key stats

  • Value for money: 5/5

    Rating

  • $0

    Starting price

  • 12

    Sources

  • Analyzed

  • Value for money: 5/5. Free core; undercuts SaaS CRM rivals
  • Ease of use: 4/5. Reviewers call it beginner-friendly
  • Feature depth: 3/5. Solid basics; light vs Salesforce/HubSpot
  • Support quality: 3/5. Fast-support praise is vendor-published only
  • Security posture: 1/5. Repeated unauthenticated LFI and XSS CVEs
  • 4.3/5 WordPress.org rating 152 reviews
  • $0 Starting price Free core plugin
  • $17/mo All extensions $199/yr full bundle
  • 30+ Extensions Modular add-ons

Pricing

Free

$0

  • Contact management
  • Sales funnels
  • Invoicing

All Extensions

$17/mo

  • 30+ extensions
  • WooCommerce integration
  • Email marketing

Full Bundle

$199/yr

  • Everything included
  • Less than $17/month

Security

Multiple CVEs (2022–2026), including unauthenticated local file inclusion; patching discipline required.

  • CVE-2026-22356: PHP local file inclusionPath traversal flaw enabling PHP local file inclusion in Automattic Jetpack CRM through version 6.7.0.⁹
  • Unauthenticated LFI, fixed in 6.7.1Unauthenticated attackers can include and execute arbitrary files on the server in versions below 6.7.1.10
  • Stored XSS in 5.4.2 and belowAuthenticated administrator stored cross-site scripting via plugin settings.11
  • CVE-2022-3342: unauthenticated code executionCode execution reachable without authentication; patched in core 4.2.4.12

What users say

Users with modest needs on WordPress sites praise its simplicity and WooCommerce tie-ins, while flagging that it stays basic.

“The Jetpack CRM looks like a good basic CRM I could recommend to friends with similar modest needs as when they needed a website.”
Reddit, r/CRM
“They tightly integrate with your Woocomerce store to track site visitors and re-target them through campaigns( like cart abandonment, etc).”
Reddit, r/CRM
“Support is fast friendly and excellent. Their plugins / addons are very reasonably priced. Jetpack CRM is so easy to understand and work with.”
Jetpack CRM reviews page (vendor-curated)

Alternatives

Compare Jetpack CRM with each alternative.

  • HubSpot CRM

    Free standalone CRM; deeper marketing tools, no WordPress dependency.

  • Zoho CRM

    Affordable standalone CRM with deeper reporting and platform independence.

  • FluentCRM

    WordPress-native alternative focused on email marketing automation.

    Jetpack CRM vs FluentCRM
  • Google Sheets

    For a handful of contacts, a spreadsheet beats any CRM.

Full analysis

Based on 20+ public sources: Reddit threads, WordPress.org, security databases, and third-party reviews. Named-company user lists absent from evidence.

Good free CRM only if you already run WordPress; repeated security CVEs and basic depth rule it out for serious teams.

Methodology

Based on 20+ public sources: Reddit threads, WordPress.org, security databases, and third-party reviews. Named-company user lists absent from evidence.

Sources

  1. official
  2. Jetpack CRM homepagejetpackcrm.com
    official
  3. official
  4. review
  5. review
  6. review
  7. review
  8. review
  9. security
  10. security
  11. security
  12. security

Rate this review

Anonymous. You can change your vote.

Loading votes…

Comments

One queue. No nested comments. Give a display name first. Limit: 200 words per comment and 7 comments per day. You can edit or delete yours.

Save a name to write a comment.

0 / 200 words

No comments yet.