shouldiuse.io

Categories

VERDICT

Should I use REDCap (Project REDCap)?

Research Electronic Data Capture — compliant data capture for clinical studies - projectredcap.org

Depends. Clinical researchers at consortium member institutions should use it — it's free and purpose-built for regulated studies. Businesses and individuals can't license it directly and should pick a commercial survey tool instead.

Confidence

Medium. Based on ~50 public sources; G2 and Reddit snippets were truncated, limiting verbatim user quotes.

Ratings

  • Value for money
  • Ease of useNo rating evidence in sources
  • Feature depth
  • Support qualitySupport varies by institution; no evidence
  • Security posture

Pricing

$0 (institutional)

Consortium membership

ModelNot disclosed
Monthly feesNot disclosed
HardwareNot disclosed
Free tierYes

Best for

  • Clinical researchers at member institutions
  • Academic medical centers running trials
  • Multi-site observational studies
  • HIPAA-regulated data collection

Not for

  • Startups and businesses — you cannot license it directly
  • Simple surveys — Google Forms does it in minutes
  • Teams with no IT staff to self-host and patch
  • Anyone outside the consortium wanting instant signup

Gotchas - check before you buy

high

Access is gated: your institution must join the consortium before anyone can use it

medium

Self-hosting puts upgrades, backups, and HIPAA compliance on your IT staff

medium

Patch cadence matters: v15.5.21 newsletter shipped major security updates

medium

Hudson Rock lists 73 infostealer credentials tied to the domain

Pros and cons

Pros

  • Free for consortium member institutions — no per-user licensing
  • Purpose-built for clinical and research data capture
  • Offline mobile capture for field sites without connectivity
  • CDIS connects studies directly to EHR systems
  • Large, active user community for workflows and troubleshooting

Cons

  • You cannot buy it — access requires institutional consortium membership
  • Typically self-hosted by institutions; your IT team owns patching and compliance
  • Historic vulnerabilities: XSS, CSRF, and SQL injection CVEs
  • Vendor security newsletters show recurring major security fixes

Sources & method

Analyzed 10/05/2026 - 10 sources - Mature program with a security page, but historical CVEs (XSS, CSRF, SQL injection) and 73 leaked credentials tied to the domain.

official x5review x2security x2news x1
  • CVE-2019-14937 — SQL injection, Vulnerability reported against REDCap in 2019.
  • CVE-2017-10962 — XSS, Cross-site scripting vulnerability reported in 2017.
  • CVE-2017-10961 — CSRF, Cross-site request forgery vulnerability reported in 2017.
  • Leaked credentials, Hudson Rock lists 73 infostealer credentials associated with.

Key stats

  • Value for money: 5/5

    Rating

  • $0 (institutional)

    Starting price

  • 10

    Sources

  • Analyzed

  • Value for money: 5/5. Free for member institutions
  • Ease of use. No rating evidence in sources
  • Feature depth: 4/5. Surveys, longitudinal databases, offline mobile, EHR interoperability
  • Support quality. Support varies by institution; no evidence
  • Security posture: 2/5. Multiple CVEs; leaked credentials tied to domain
  • $0 Price for consortium member institutions
  • Yes Free tier via institutional membership
  • 221 G2 reviews across product and seller pages
  • 3 Public CVEs found XSS, CSRF, SQL injection (2017–2019)

Pricing

Consortium membership

$0 (institutional)

  • Software available at no cost to member institutions
  • Self-hosted or consortium-supported deployment
  • Access only after your institution joins

Security

Mature program with a security page, but historical CVEs (XSS, CSRF, SQL injection) and 73 leaked credentials tied to the domain.

  • CVE-2019-14937 — SQL injectionVulnerability reported against REDCap in 2019.⁷
  • CVE-2017-10962 — XSSCross-site scripting vulnerability reported in 2017.
  • CVE-2017-10961 — CSRFCross-site request forgery vulnerability reported in 2017.
  • Leaked credentialsHudson Rock lists 73 infostealer credentials associated with.⁸

What users say

221 G2 reviews exist and an active Reddit community trades workflows, but source snippets reveal little verbatim sentiment.

Companies that use it

  • Johns Hopkins⁹
  • Baylor College of Medicine
  • Yale University
  • UC Davis Health
  • Texas Tech University
Full analysis

Based on ~50 public sources; G2 and Reddit snippets were truncated, limiting verbatim user quotes.

Free, clinical-grade data capture for consortium universities — businesses can't buy in; access is institution-gated.

Methodology

Based on ~50 public sources; G2 and Reddit snippets were truncated, limiting verbatim user quotes.

Sources

  1. Join & Get REDCapprojectredcap.org
    official
  2. REDCap Softwareprojectredcap.org
    official
  3. official
  4. official
  5. review
  6. r/ProjectREDCapreddit.com
    review
  7. security
  8. security
  9. news
  10. official

Rate this review

Anonymous. You can change your vote.

Loading votes…

Comments

One queue. No nested comments. Give a display name first. Limit: 200 words per comment and 7 comments per day. You can edit or delete yours.

Save a name to write a comment.

0 / 200 words

No comments yet.