shouldiuse.io

VERDICT

Should I use LinkAce?

Free and open source bookmark archive for long-term storage and organization of your favorite links. - linkace.org

Depends. Buy it if you already self-host and want links archived under your own control forever. Skip it if you want zero-maintenance hosted bookmarking.

Confidence

Medium. Based on ~25 public sources; many review snippets were truncated, so quotes are partial.

Ratings

  • Value for money
  • Ease of use
  • Feature depth
  • Support quality
  • Security posture

Pricing

Free

Self-hosted

ModelNot disclosed
Monthly feesNot disclosed
HardwareNot disclosed
Free tierYes

Best for

  • Self-hosters on Docker
  • Long-term link archiving
  • Privacy-focused bookmark hoarders
  • People who own their data

Not for

  • Non-technical users — you must run a server
  • Teams wanting hosted, zero-maintenance bookmarking
  • Anyone who won't track and apply security patches
  • Casual savers — browser bookmarks or Raindrop are enough

Gotchas - check before you buy

high

You handle updates, backups, and security patches yourself — old installs are risky

high

Multiple CVEs published 2024–2026, including a high-severity SSRF

medium

Docker setup issues are a recurring Reddit complaint

low

Free app, but hosted convenience means paying VPS costs

Pros and cons

Pros

  • Free and open source, no subscription ever
  • Self-hosted archive built for long-term link storage
  • Actively developed; version 2.0 shipped
  • Strong community traction on r/selfhosted
  • API enables saving links via iOS Shortcuts

Cons

  • Self-hosting required: server, Docker, backups, maintenance
  • Docker advanced install instructions have tripped up users
  • Steady stream of CVEs to track and patch
  • Solo-maintainer open source project; support is community-only

Sources & method

Analyzed 9/21/2026 - 11 sources - Multiple CVEs across 2024–2026 (SSRF, stored XSS, information disclosure); fixed in newer releases — run the latest version.

official x4review x4security x3
  • SSRF vulnerability (CVE-2026-30953), Rated high severity by third-party trackers.
  • Stored XSS via javascript: URI in Bulk Link API (CVE-2026-49436), Authenticated stored XSS through link URLs.
  • Stored XSS prior to 2.5.6 (CVE-2026-45343), Patched in version 2.5.6.
  • File upload XSS in v1.15.5 (GHSA-2wvv-4576-8862), File upload leading to cross-site scripting; fixed after disclosure.

Key stats

  • Value for money: 5/5

    Rating

  • Free

    Starting price

  • 11

    Sources

  • Analyzed

  • Value for money: 5/5. Free and open source, no subscription
  • Ease of use: 3/5. Clean UI, but Docker setup confuses users
  • Feature depth: 4/5. API, Zapier integrations, automated archiving, tags
  • Support quality: 2/5. Community docs and forums; no vendor support
  • Security posture: 2/5. Repeated CVEs 2024–2026; patch fast
  • $0 Price Free and open source
  • 333 upvotes r/selfhosted launch One thread, 32 comments
  • 246 upvotes Earlier thread 50 comments on r/selfhosted
  • v2.0 Latest release Major rewrite shipped

Pricing

Self-hosted

Free

  • Full open source application
  • You supply and run the server
  • Docker or manual install

Security

Multiple CVEs across 2024–2026 (SSRF, stored XSS, information disclosure); fixed in newer releases — run the latest version.

  • SSRF vulnerability (CVE-2026-30953)Rated high severity by third-party trackers.⁸
  • Stored XSS via javascript: URI in Bulk Link API (CVE-2026-49436)Authenticated stored XSS through link URLs.
  • Stored XSS prior to 2.5.6 (CVE-2026-45343)Patched in version 2.5.6.10
  • File upload XSS in v1.15.5 (GHSA-2wvv-4576-8862)File upload leading to cross-site scripting; fixed after disclosure.⁹

What users say

The self-hosting community praises its design and long-term archiving, while setup friction is the recurring complaint.

“LinkAce is not only beautiful to look at but also...”
Noted.lol review
“Hello, I've followed the instructables for the docker advanced install”
Reddit, r/selfhosted
Full analysis

Based on ~25 public sources; many review snippets were truncated, so quotes are partial.

Free self-hosted bookmark archive beloved by self-hosters. Skip if you won't run a server or patch CVEs.

Methodology

Based on ~25 public sources; many review snippets were truncated, so quotes are partial.

Sources

  1. official
  2. official
  3. official
  4. review
  5. review
  6. review
  7. review
  8. CVE-2026-30953 SSRFsentinelone.com
    security
  9. security
  10. security
  11. official

Rate this review

Anonymous. You can change your vote.

Loading votes…

Comments

One queue. No nested comments. Give a display name first. Limit: 200 words per comment and 7 comments per day. You can edit or delete yours.

Save a name to write a comment.

0 / 200 words

No comments yet.