shouldiuse.io

VERDICT

Should I use OneUptime?

Detect outages in seconds, page the right engineer, update your status page, and ship the fix — open-source observability and incident management. - oneuptime.com

Depends. Buy if you're an engineering team wanting Datadog/PagerDuty scope under open-source licensing and can run it yourself. Skip if you only need simple uptime checks, hand-holding support, or strict security vetting.

Confidence

Medium. Based on 20+ public sources; several review snippets were truncated, and no named customers appeared in the evidence.

Ratings

  • Value for money
  • Ease of useNo direct usability evidence in sources.
  • Feature depth
  • Support quality
  • Security posture

Pricing

Free

Open source (self-hosted)

ModelNot disclosed
Monthly feesNot disclosed
HardwareNot disclosed
Free tierYes
Cloud (usage-based)From $20

Best for

  • DevOps teams ditching Datadog bills
  • Open-source / self-host shops
  • Teams bundling uptime, on-call, status page
  • Engineering-led startups with on-call rotations

Not for

  • Teams needing only simple uptime checks — Uptime Kuma does it for free
  • Non-technical teams; self-hosting and upgrades demand real ops skill
  • Buyers who need responsive vendor support
  • Strict-security orgs unwilling to vet its CVE history

Gotchas - check before you buy

high

Security track record: several critical CVEs in the past year — patch self-hosted deployments fast.

medium

Self-hosting runs many services; upgrades need careful migration steps or you risk losing history.

medium

$20 usage-pricing unit isn't fully public — confirm exact metering before committing.

medium

Support responsiveness flagged in a G2 review; test it before an enterprise commitment.

Pros and cons

Pros

  • 100% open source; full platform can be self-hosted free.
  • Replaces a whole shelf of SaaS: uptime, on-call, status, logs, traces.
  • Positions as open-source alternative to Datadog, PagerDuty,.
  • Usage-based cloud pricing starting around $20.
  • Backed by Y Combinator; active development and frequent releases.

Cons

  • Multiple critical CVEs 2025–26: RCE, command injection, SQLi, privilege escalation.
  • G2 reviewer reports unhelpful support when seeking help.
  • Self-hosted upgrades require careful, multi-step data migration.
  • Mixed Reddit reception; some users explicitly dislike the product.

Sources & method

Analyzed 9/20/2026 - 14 sources - Active 2025–2026 CVE history including critical RCE/command injection and privilege escalation; fixes appear shipped, but vet before sensitive deployments.

official x3review x6security x4news x1
  • CVE-2026-27574 — Remote Code Execution, Public proof-of-concept repository describing RCE in OneUptime.
  • CVE-2026-32306 — SQL injection, SQLi vulnerability in OneUptime reported by SentinelOne.
  • CVE-2025-66028 — Privilege escalation, Authentication response flaw enabling privilege escalation.
  • Critical command injection (March 2026), Critical command injection vulnerability reported by GBHackers.

Key stats

  • Value for money: 4/5

    Rating

  • Free

    Starting price

  • 14

    Sources

  • Analyzed

  • Value for money: 4/5. Open source plus usage pricing undercuts Datadog-class bills.
  • Ease of use. No direct usability evidence in sources.
  • Feature depth: 5/5. Uptime, on-call, status, logs, traces bundled together.
  • Support quality: 2/5. G2 review cites unhelpful support response.
  • Security posture: 2/5. Multiple critical 2025–26 CVEs, including RCE.
  • 4.4/5 AppSumo rating 7 reviews
  • From $20 (usage-based) Starting price Unit not fully shown in sources
  • Yes Free tier 100% open source, self-hostable
  • Y Combinator Backing VC-backed startup

Pricing

Open source (self-hosted)

Free

  • Full observability and incident platform
  • You operate, secure, and upgrade it

Cloud (usage-based)

From $20

  • Simple usage pricing; metering unit not shown in sources
  • Growth plan also listed in comparisons

Security

Active 2025–2026 CVE history including critical RCE/command injection and privilege escalation; fixes appear shipped, but vet before sensitive deployments.

  • CVE-2026-27574 — Remote Code ExecutionPublic proof-of-concept repository describing RCE in OneUptime.
  • CVE-2026-32306 — SQL injectionSQLi vulnerability in OneUptime reported by SentinelOne.⁹
  • CVE-2025-66028 — Privilege escalationAuthentication response flaw enabling privilege escalation.
  • Critical command injection (March 2026)Critical command injection vulnerability reported by GBHackers.10

What users say

Praise centers on it being an awesome open-source bargain, while Reddit and G2 voices report dislikes and weak support.

“OneUptime is awesome! It's sup...”
AppSumo review
“Did not like the product and...”
Reddit, r/OpenTelemetry
“When I tried to get help the OneUptim...”
G2 review
Full analysis

Based on 20+ public sources; several review snippets were truncated, and no named customers appeared in the evidence.

Open-source Datadog/PagerDuty rival with real depth — but heavy self-hosting, thin support, and a pile of critical CVEs.

Methodology

Based on 20+ public sources; several review snippets were truncated, and no named customers appeared in the evidence.

Sources

  1. official
  2. OneUptime pricingoneuptime.com
    official
  3. official
  4. review
  5. review
  6. review
  7. review
  8. review
  9. security
  10. security
  11. security
  12. security
  13. review
  14. Who Funded OneUptime — YC backingbilliondollarpitchdecks.com
    news

Rate this review

Anonymous. You can change your vote.

Loading votes…

Comments

One queue. No nested comments. Give a display name first. Limit: 200 words per comment and 7 comments per day. You can edit or delete yours.

Save a name to write a comment.

0 / 200 words

No comments yet.