shouldiuse.io

VERDICT

Should I use Telerik?

Save time building sleek web, mobile and desktop apps with professional .NET UI Components, JavaScript UI Libraries, Reporting and Automated Testing solutions. - telerik.com

Depends. Buy if you're an enterprise .NET team building complex, data-heavy UIs and can commit to prompt security patching. Skip it if you're a solo dev or small team — free component libraries and simpler stacks cover simple apps.

Confidence

Medium. Based on ~20 public sources; no concrete price figures found in reviewed pages.

Ratings

  • Value for money
  • Ease of use
  • Feature depth
  • Support quality
  • Security posture

Pricing

Not disclosed

ModelSubscription
Monthly feesNot disclosed
HardwareNot disclosed

Best for

  • Enterprise .NET teams
  • Data-heavy internal apps
  • Blazor and shops
  • Teams needing built-in reporting

Not for

  • Solo devs and hobby projects
  • Small apps fine with free libraries
  • Teams that won't patch CVEs promptly
  • Buyers who need perpetual licenses

Gotchas - check before you buy

high

Perpetual licenses dropped — recurring subscription cost for the life of the app

high

UI for AJAX RCE (CVSS 8.1); unpatched versions are actively targeted

high

CVE-2019-18935 sits in CISA's KEV — attackers exploit unpatched installs

medium

Removing Telerik from legacy apps is painful enough that admins seek workarounds

Pros and cons

Pros

  • Huge breadth: web, mobile, desktop, reporting, testing components
  • Blazor users call it a game-changer for web development
  • Support praised as excellent by long-time users
  • Rich docs, demos and developer hub
  • 554 companies tracked using Telerik UI

Cons

  • Multiple RCE and deserialization CVEs, some actively exploited
  • Perpetual licensing discontinued — subscription only going forward
  • WinForms suite criticized for slow controls and weak support
  • Legacy AJAX line carries the bulk of CVE history

Sources & method

Analyzed 9/21/2026 - 10 sources - Flagged: repeated high-severity CVEs including unauthenticated RCE — patching discipline is mandatory.

official x1review x4security x3news x2
  • CVE-2026-13185: UI for AJAX unauthenticated RCE, Chained vulnerabilities allow remote code execution; CVSS 8.1.
  • CVE-2026-6023: deserialization of untrusted data, Affects UI for AJAX versions 2024.4.1114 through 2026.1.4.
  • CVE-2024-1801 / CVE-2024-1856: Telerik Reporting, Insecure deserialization vulnerabilities requiring mitigation steps.
  • CVE-2019-18935: CISA KEV listing, Older Telerik UI versions actively exploited in the wild per CISA alert AA23-074A.

Key stats

  • Value for money: 3/5

    Rating

  • Not disclosed

    Starting price

  • 10

    Sources

  • Analyzed

  • Value for money: 3/5. Perpetual licenses dropped; costs recur annually
  • Ease of use: 3/5. Some report sluggish controls in WinForms
  • Feature depth: 5/5. Massive suite: web, mobile, desktop, reporting, testing
  • Support quality: 3/5. Praised by some, panned in WinForms
  • Security posture: 2/5. Repeated RCE/deserialization CVEs; CISA KEV listed
  • 554 Companies tracked using Telerik UI per TheirStack technology index
  • CVSS 8.1 Worst CVE severity in sources UI for AJAX RCE, CVE-2026-13185
  • Subscription Pricing model perpetual licenses discontinued
  • Progress Software Ownership acquired Telerik; formerly Summit Partners-backed

Pricing

Not disclosed

Security

Flagged: repeated high-severity CVEs including unauthenticated RCE — patching discipline is mandatory.

  • CVE-2026-13185: UI for AJAX unauthenticated RCEChained vulnerabilities allow remote code execution; CVSS 8.1.⁷
  • CVE-2026-6023: deserialization of untrusted dataAffects UI for AJAX versions 2024.4.1114 through 2026.1.4.
  • CVE-2024-1801 / CVE-2024-1856: Telerik ReportingInsecure deserialization vulnerabilities requiring mitigation steps.
  • CVE-2019-18935: CISA KEV listingOlder Telerik UI versions actively exploited in the wild per CISA alert AA23-074A.⁸

Alternatives

Compare Telerik with each alternative.

  • MudBlazor

    Free open-source Blazor components; enough for most internal apps.

    Telerik vs MudBlazor
  • Fluent UI (Blazor)

    Microsoft's free Fluent components; standard look, zero licensing cost.

  • Syncfusion

    Guess: comparable paid .NET suite, sometimes cheaper per developer.

Companies that use it

  • Insperity
  • Canyon Digital Solutions
  • LaunchStar
Full analysis

Based on ~20 public sources; no concrete price figures found in reviewed pages.

Powerful, pricey .NET component suite: great for serious enterprise dev teams, overkill for small apps.

Methodology

Based on ~20 public sources; no concrete price figures found in reviewed pages.

Sources

  1. official
  2. review
  3. review
  4. review
  5. review
  6. security
  7. security
  8. security
  9. news
  10. news

Rate this review

Anonymous. You can change your vote.

Loading votes…

Comments

One queue. No nested comments. Give a display name first. Limit: 200 words per comment and 7 comments per day. You can edit or delete yours.

Save a name to write a comment.

0 / 200 words

No comments yet.