Should I use Snipe-IT?
Snipe-IT is a free, open source IT asset management system written in PHP - snipeitapp.com
Depends. Buy if you're an IT team tracking real device inventory and someone can host and patch it. Skip if you have a handful of laptops and no one technical — a spreadsheet wins.
Confidence
Medium. Based on ~14 public sources; no third-party star ratings or review counts found.
Ratings
- Value for money
- Ease of use
- Feature depth
- Support quality
- Security posture
Pricing
$0
Self-hosted (open source)
ModelNot disclosed
Monthly feesNot disclosed
HardwareNot disclosed
Free tierYes
Hosted / support plansNot published in sources
Best for
- →IT teams tracking laptops, licenses, accessories
- →Self-hosters wanting on-prem control
- →Orgs outgrowing asset spreadsheets
- →Hybrid Azure AD shops comfortable scripting
Not for
- ×Tiny teams with a few devices — spreadsheet wins
- ×Non-technical buyers with nobody to host and patch PHP
- ×Teams wanting turnkey managed SaaS without paying
- ×Buyers needing vendor SLAs and hand-holding
Gotchas - check before you buy
high
Known authorization-bug CVE means lagging patches on your instance is a real risk
medium
'Free' means self-hosted; hosted and support plans are paid, with prices not published
low
No SLA or support-quality details found in public sources; budget support plans separately
Pros and cons
Pros
- +Completely free forever if you self-host
- +Open source: transparent, no vendor lock-in
- +Tracks assets, software licenses, and accessories in one system
- +Sysadmins repeatedly recommend it for on-prem tracking
- +Easy to automate via scripts and integrations
Cons
- −You host it: PHP stack, upgrades, and backups are your job
- −Two public CVEs found; patching discipline is on you
- −Vendor hosting and support cost extra
- −Hybrid Azure AD sync needs custom scripting, per user reports
Sources & method
Analyzed 9/24/2026 - 10 sources - Open source with a security page; two CVEs found in sources, including an authorization flaw.
official x4review x4security x2
- CVE-2025-63743, Medium-severity vulnerability reported in Snipe-IT; details limited in sources reviewed.
- CVE-2026-38533, Authorization-related vulnerability in Snipe-IT (Grokability, Inc.) listed in JVN database; PoC publicly referenced.
Comments
One queue. No nested comments. Give a display name first. Limit: 200 words per comment and 7 comments per day. You can edit or delete yours.
No comments yet.