shouldiuse.io

Categories

VERDICT

Should I use OpenSign?

Open-source DocuSign alternative for secure PDF document signing with encryption, API support, and no hefty price tag. - opensignlabs.com

Depends. Buy if you're a technical team or cost-sensitive small business comfortable self-hosting and patching fast. Skip if you sign sensitive contracts and need audited security or vendor-backed support — the 2026 CVEs are a real red flag.

Confidence

Medium. Based on ~20 public sources. Review snippets were truncated, so no numeric ratings could be extracted; cloud pricing figures were not published in sources reviewed.

Ratings

  • Value for money
  • Ease of use
  • Feature depth
  • Support quality
  • Security posture

Pricing

$0

Open-source (self-hosted)

ModelNot disclosed
Monthly feesNot disclosed
HardwareNot disclosed
Free tierYes
Cloud plansNot published in sources reviewed

Best for

  • Cost-sensitive small businesses
  • Self-hosters and dev teams
  • API-driven document workflows
  • Startups cutting DocuSign spend

Not for

  • Legal, healthcare, finance teams needing audited compliance
  • Non-technical teams unwilling to self-host and patch
  • Enterprises needing SLA-backed vendor support
  • Anyone signing high-stakes contracts without a security review

Gotchas - check before you buy

high

Self-hosting means you own patching; 2026 CVEs show updates lag exploitability

medium

Cloud plan pricing not published in sources reviewed — confirm costs before committing

medium

Open-source governance dispute; verify who maintains the repo you deploy

medium

Support quality unproven; Trustpilot reviews average, no SLA evidence

Pros and cons

Pros

  • Free, open-source core undercuts DocuSign's per-envelope pricing
  • Self-hostable; strong r/selfhosted interest (96 upvotes on launch thread)
  • Robust API, templates, webhooks, and OpenSign Drive included
  • Capterra users call it the best alternative

Cons

  • Multiple 2026 CVEs, including authentication bypass
  • Vendor security page returning 404 at review time
  • Trustpilot sentiment only 'Average' (Aug 2024)
  • Public governance drama: attempted project hijack disclosed on Reddit

Sources & method

Analyzed 10/03/2026 - 13 sources - Multiple CVEs published in 2026 including auth bypass and unauthenticated tenant data exposure; vendor security page was returning a 404.

official x4review x4security x4news x1
  • CVE-2026-72545 — Auth bypass, Authentication bypass vulnerability in OpenSign disclosed Aug 2026.
  • CVE-2026-72548 — Unauthenticated tenant data access, Unauthenticated tenant data vulnerability disclosed Aug 2026.
  • CVE-2026-92794 — Information disclosure, Missing authorization (CWE-862) information disclosure; affects OpenSign ≤ 2.41.3.
  • CVE-2026-72549 / CVE-2026-72544, Information disclosure and integrity issues disclosed Aug 2026.

Key stats

  • Value for money: 5/5

    Rating

  • $0

    Starting price

  • 13

    Sources

  • Analyzed

  • Value for money: 5/5. Free open-source core beats DocuSign pricing
  • Ease of use: 3/5. Marketed user-friendly; self-host setup adds friction
  • Feature depth: 3/5. Templates, API, webhooks; less breadth than DocuSign
  • Support quality: 3/5. Trustpilot sentiment 'Average'; no SLA evidence
  • Security posture: 2/5. Five-plus 2026 CVEs including auth bypass
  • $0 Starting price Self-hosted open-source core
  • Yes Free tier Open-source self-host; paid cloud plans exist
  • 5+ 2026 published CVEs Incl. auth bypass and tenant data exposure

Pricing

Open-source (self-hosted)

$0

  • Unlimited self-hosted signing
  • Community support
  • You manage updates and security

Cloud plans

Not published in sources reviewed

  • Managed hosting via OpenSign Labs
  • Check plans-pricing page for current rates

Security

Multiple CVEs published in 2026 including auth bypass and unauthenticated tenant data exposure; vendor security page was returning a 404.

  • CVE-2026-72545 — Auth bypassAuthentication bypass vulnerability in OpenSign disclosed Aug 2026.10
  • CVE-2026-72548 — Unauthenticated tenant data accessUnauthenticated tenant data vulnerability disclosed Aug 2026.11
  • CVE-2026-92794 — Information disclosureMissing authorization (CWE-862) information disclosure; affects OpenSign ≤ 2.41.3.12
  • CVE-2026-72549 / CVE-2026-72544Information disclosure and integrity issues disclosed Aug 2026.

What users say

Self-hosters on Reddit praise the free, quick setup, and Capterra reviewers are positive, but Trustpilot sentiment is average and review snippets lack ratings.

“opensign is much better”
GitHub, docusealco/docuseal discussion
“OpenSign is the best al…”
Capterra (AU) review
Full analysis

Based on ~20 public sources. Review snippets were truncated, so no numeric ratings could be extracted; cloud pricing figures were not published in sources reviewed.

Free open-source DocuSign rival: great price, but 2026 auth-bypass CVEs make it dicey for sensitive contracts.

Methodology

Based on ~20 public sources. Review snippets were truncated, so no numeric ratings could be extracted; cloud pricing figures were not published in sources reviewed.

Sources

  1. OpenSign homepageopensignlabs.com
    official
  2. OpenSign pricingopensignlabs.com
    official
  3. official
  4. official
  5. review
  6. Trustpilot reviewstrustpilot.com
    review
  7. Capterra (AU) reviewscapterra.com.au
    review
  8. review
  9. news
  10. security
  11. security
  12. security
  13. security

Rate this review

Anonymous. You can change your vote.

Loading votes…

Comments

One queue. No nested comments. Give a display name first. Limit: 200 words per comment and 7 comments per day. You can edit or delete yours.

Save a name to write a comment.

0 / 200 words

No comments yet.