shouldiuse.io

VERDICT

Should I use SolidInvoice?

Professional invoicing for freelancers & small businesses. Online payments, recurring billing, automated reminders. From $9/mo with a 14-day free trial. - solidinvoice.co

Depends. A solid $9/mo fit for freelancers who only need invoicing, recurring billing, and payments — especially if the free self-hosted version appeals. Skip it if you need full accounting, phone support, or can't keep a self-hosted instance patched against its repeat CVEs.

Confidence

Medium. Based on 40+ public sources: official site and pricing pages, GitHub, Reddit threads, CVE/NVD databases, and third-party comparison sites.

Ratings

  • Value for money
  • Ease of use
  • Feature depth
  • Support qualityOnly email support documented; no user reports
  • Security posture

Pricing

Free

Open source (self-hosted)

ModelNot disclosed
Monthly feesNot disclosed
HardwareNot disclosed
Free tierYes
Solo$9/mo
Pro$19/mo

Best for

  • Freelancers invoicing on a budget
  • Self-hosters (Docker, NAS, Proxmox)
  • Side businesses replacing spreadsheet billing
  • QuickBooks refugees needing invoicing only

Not for

  • Anyone needing full accounting: payroll, taxes, books
  • Self-hosters who won't apply security patches promptly
  • Enterprises needing SOC 2, audit trails, or compliance
  • Buyers wanting phone support and vendor hand-holding

Gotchas - check before you buy

high

Multiple 2026 CVEs (token access, XSS, deserialization). Self-hosters must run latest version or risk compromise.

medium

Third-party listed a $20/mo starting price in 2025; site now shows $9. Confirm current pricing before committing.

medium

Pricing page mentions email support only; no phone or chat advertised.

low

Guess: 14-day trial may end before a monthly recurring invoice cycle completes.

Pros and cons

Pros

  • From $9/mo; far cheaper than QuickBooks' $35/mo
  • Free self-hosted open-source version with Docker support
  • Recurring billing, online payments, automated reminders included
  • 14-day free trial on hosted plans
  • Mature, production-ready codebase built on Symfony

Cons

  • Repeated 2025–2026 CVEs, including RCE-class deserialization
  • API tokens stored as plaintext in the database
  • Self-hosted installs confuse beginners
  • No outside funding; small-team longevity risk
  • Tiny community: 894 GitHub stars limits ecosystem help

Sources & method

Analyzed 9/20/2026 - 12 sources - Active CVE history in 2025–2026: RCE-class deserialization, stored XSS, cross-user token access, and plaintext API tokens. Patch promptly; never run outdated self-hosted builds.

official x4review x4security x3news x1
  • CVE-2026-61686 — insecure deserialization (RCE-class), PHP deserialization of untrusted data reported in SolidInvoice.
  • Plaintext API token storage, May 2026 advisory: API tokens stored unencrypted in the database, impacting all users.
  • CVE-2026-61688 — cross-user API token access, Cross-user access to API token request endpoints; CVSS 6.5, disclosed Sept 2026.
  • CVE-2026-46489 — stored XSS via logo upload, Stored XSS through unvalidated logo upload in versions before 2.3.17.
  • CVE-2025-55580 — stored XSS in 2.3.7, Stored cross-site scripting vulnerability in version 2.3.7.

Key stats

  • Value for money: 5/5

    Rating

  • Free

    Starting price

  • 12

    Sources

  • Analyzed

  • Value for money: 5/5. Free self-hosted tier; $9 beats QuickBooks' $35
  • Ease of use: 3/5. Simple app; self-host setup confuses novices
  • Feature depth: 3/5. Invoicing, recurring, payments; no full accounting
  • Support quality. Only email support documented; no user reports
  • Security posture: 1/5. RCE-class CVE and plaintext token storage
  • $9/mo Starting price Solo plan; Pro at $19/mo
  • Yes Free option Open-source self-hosted; 14-day hosted trial
  • 894 GitHub stars Small open-source community
  • None raised Funding Independent, per Tracxn

Pricing

Open source (self-hosted)

Free

  • Full invoicing app you host yourself
  • Docker and NAS install guides

Solo

$9/mo

  • Hosted invoicing
  • Email support
  • 14-day free trial

Pro

$19/mo

  • Hosted invoicing for growing businesses
  • 14-day free trial

Security

Active CVE history in 2025–2026: RCE-class deserialization, stored XSS, cross-user token access, and plaintext API tokens.

  • CVE-2026-61686 — insecure deserialization (RCE-class)PHP deserialization of untrusted data reported in SolidInvoice.⁵
  • Plaintext API token storageMay 2026 advisory: API tokens stored unencrypted in the database, impacting all users.⁴

Patch promptly; never run outdated self-hosted builds.

  • CVE-2026-61688 — cross-user API token accessCross-user access to API token request endpoints; CVSS 6.5, disclosed Sept 2026.⁶
  • CVE-2026-46489 — stored XSS via logo uploadStored XSS through unvalidated logo upload in versions before 2.3.17.
  • CVE-2025-55580 — stored XSS in 2.3.7Stored cross-site scripting vulnerability in version 2.3.7.⁷

What users say

Reddit discussion centers on self-hosting SolidInvoice via Docker, NAS, and Proxmox; users find it simple and free but installation trips up novices.

“Simple and elegant invoicing solution.”
GitHub project listing
“I have never installed any programs before so I'm a…”
Reddit, r/synology
Full analysis

Based on 40+ public sources: official site and pricing pages, GitHub, Reddit threads, CVE/NVD databases, and third-party comparison sites.

Cheap invoicing-only tool with a free self-hosted option; repeat 2025–26 CVEs make patching mandatory. Not accounting.

Methodology

Based on 40+ public sources: official site and pricing pages, GitHub, Reddit threads, CVE/NVD databases, and third-party comparison sites.

Sources

  1. official
  2. official
  3. official
  4. official
  5. security
  6. security
  7. security
  8. review
  9. review
  10. review
  11. news
  12. review

Rate this review

Anonymous. You can change your vote.

Loading votes…

Comments

One queue. No nested comments. Give a display name first. Limit: 200 words per comment and 7 comments per day. You can edit or delete yours.

Save a name to write a comment.

0 / 200 words

No comments yet.