shouldiuse.io

Report

Should I Use StackStorm?

stackstorm.com·Analyzed 1 hour ago·Based on 2 sources

StackStorm connects all your apps, services, and workflows.

Depends

Depends

Buy it if you're a DevOps or platform team that wants powerful, self-hosted open-source workflow automation and can patch it promptly.

Powerful open-source DevOps automation. Great for platform teams who self-host; overkill for small teams — try Zapier or n8n.

Confidence: Low

Open source

License

Free to self-host

5

Disclosed CVEs

High severity, 2019–2022, all fixed

≤48h

Security response

Acknowledgment of reported issues

Value for money4

Open-source core, free to self-host

Feature depth4

Rules to complex workflows; broad integration claims

Security posture3

Transparent fixes, but 5 high CVEs 2019–2022

Pros

  • Handles everything from simple if/then rules to complex workflows¹
  • Integrates with existing infrastructure without changing current processes¹
  • Open source with enterprise pedigree¹
  • Transparent, responsible security disclosure with 48-hour acknowledgment²

Cons

  • Five high-severity CVEs disclosed between 2019 and 2022²
  • Older versions allowed arbitrary code execution via Jinja (CVE-2021-44657)²
  • Staying safe requires prompt upgrades to the latest release²

Gotchas

  • highRBAC bypass (CVE-2022-44009) existed even with RBAC enabled; fixed only in v3.8.0²
  • highWeb UI XSS via rule injection affected all versions before 3.8.0²
  • highRunning anything but the latest release leaves you exposed to known exploits²
  • mediumGuess: no paid tiers surfaced — expect community support, not vendor SLAs¹

Best for

  • DevOps and platform engineering teams
  • Ops teams gluing many internal tools
  • Enterprises wanting self-hosted open-source orchestration

Not for

  • Small teams that just need Zapier-style app automation
  • Non-technical users wanting a no-code interface
  • Teams with no engineers to install, run, and patch it
  • Buyers wanting a managed SaaS with vendor support

Pricing

Open source (self-hosted)

Free

  • Full rules and workflow automation engine
  • Integrations with existing infrastructure

Security

Transparent responsible disclosure; 5 high-severity CVEs (2019–2022), all fixed by v3.8.0 — run the latest release.

  • CVE-2022-44009 — RBAC bypass on K/V datastoreVersion 3.7.0 didn't check permissions in Jinja filters, exposing other users' K/V pairs. Fixed in v3.8.0.²
  • CVE-2022-43706 — Web UI XSS via rules injectionUsers with rule write access could inject scripts executed in other users' browsers. Affected all versions before 3.8.0.²
  • CVE-2021-44657 — Unsandboxed Jinja allowed arbitrary code executionJinja ran without sandbox before 3.6.0, letting logged-in users execute unsafe system commands.²
  • CVE-2021-28667 — Logging infinite loop causing DoSBefore 3.4.1, logging Unicode in certain locales could exhaust memory and disk.²
  • CVE-2019-9580 — CORS protection bypassListed on the security page; details truncated in the source reviewed.²

What users say

No independent user reviews or community quotes were found in the sources reviewed.

Alternatives

Compare StackStorm with each alternative.

Ansible

Simpler config management and automation for DevOps

Rundeck

Ops runbook automation with friendlier operations UI

Full analysis

Based on 2 public sources; no independent reviews, pricing pages, or named customers found.

Sources

  1. StackStorm homepagestackstorm.com
    official
  2. security

Rate this review

Anonymous. You can change your vote.

Loading votes…

Ask a follow-up

Ask if a use case fits. Answers stay inside this report and its sources.