shouldiuse.io

Categories

VERDICT

Should I use Typora?

A new way to read & write markdown. - typora.io

Worth it. Buy it if you're a solo writer or developer who wants a fast, distraction-free Markdown editor for a one-time $15. Don't if you need team collaboration, cloud sync, an open-source license, or vendor security documentation.

Confidence

Medium. Based on 20+ public sources: G2 reviews, Reddit and Hacker News threads, CVE databases, and official Typora pages.

Ratings

  • Value for money
  • Ease of use
  • Feature depth
  • Support qualityNo support-quality evidence in sources
  • Security posture

Pricing

$15 one-time

Personal license

ModelNot disclosed
Monthly feesNot disclosed
HardwareNot disclosed
Free tierNo

Best for

  • Solo writers in Markdown
  • Bloggers publishing to HTML/PDF
  • Developers writing docs and READMEs
  • People fleeing bloated note apps

Not for

  • Teams needing real-time collaboration or cloud sync
  • Anyone requiring free or open-source software
  • Knowledge-base users wanting backlinks and graphs
  • Security-strict orgs needing SSO or a security page

Gotchas - check before you buy

high

Several CVEs across 2023–2024 (XSS, command injection); update promptly

medium

Free-to-paid switch upset users; some left for open-source alternatives

medium

Vendor opacity: users publicly ask who is behind Typora

medium

Support is email and GitHub issues only; tiny team, no SLA

Pros and cons

Pros

  • Live rendering: write and see formatted output in one view
  • $15 one-time license, no subscription
  • G2 4.3/5; praised as minimal and distraction-free
  • Cross-platform: macOS, Windows, Linux (Flathub, Snap, Microsoft Store)

Cons

  • No longer free since v1.0 (2021)
  • Closed source; no public product security page
  • No organizational or team features
  • Recurring CVEs: XSS, command injection, file disclosure

Sources & method

Analyzed 9/26/2026 - 12 sources - Multiple CVEs in 2023–2024 (XSS, command injection, local file disclosure); no security page.

official x2review x5security x4news x1
  • CVE-2023-2317: DOM-based XSS, DOM-based cross-site scripting vulnerability in Typora.
  • CVE-2024-41481: XSS before v1.9.3, Cross-site scripting in Typora before 1.9.3.
  • Command injection in v1.7.4 via PDF export, OS command injection via Export PDF and preferences.
  • CVE-2023-2971: local file disclosure (patch bypass), Local file read vulnerability with an initial patch bypass.

Key stats

  • Value for money: 5/5

    Rating

  • $15 one-time

    Starting price

  • 12

    Sources

  • Analyzed

  • Value for money: 5/5. $15 one-time beats subscriptions
  • Ease of use: 5/5. Reviewers praise seamless, minimal writing
  • Feature depth: 3/5. Minimal by design; few org features
  • Support quality. No support-quality evidence in sources
  • Security posture: 2/5. Multiple XSS and injection CVEs
  • 4.3/5 G2 rating 11 reviews
  • $15 Price one-time, lifetime license
  • No Free tier paid since v1.0 (late 2021)
  • 6+ Public CVEs 2023–2024: XSS, injection, file disclosure

Pricing

Personal license

$15 one-time

  • Lifetime license, no subscription
  • macOS, Windows, Linux

Security

Multiple CVEs in 2023–2024 (XSS, command injection, local file disclosure); no security page.

  • CVE-2023-2317: DOM-based XSSDOM-based cross-site scripting vulnerability in Typora.⁸
  • CVE-2024-41481: XSS before v1.9.3Cross-site scripting in Typora before 1.9.3.11
  • Command injection in v1.7.4 via PDF exportOS command injection via Export PDF and preferences.⁹
  • CVE-2023-2971: local file disclosure (patch bypass)Local file read vulnerability with an initial patch bypass.10

What users say

Users love the minimal, seamless live-rendering writing experience and consider $15 fair; gripes center on the move to paid and missing organization features.

“Typora: a markdown writer's soul mate”
Medium
“I happily paid money for Typora”
Hacker News
“Typora is a minimal markdown editor”
Reddit, r/freesoftware
Full analysis

Based on 20+ public sources: G2 reviews, Reddit and Hacker News threads, CVE databases, and official Typora pages.

$15 one-time Markdown editor writers rave about. Not for teams, open-source purists, or security-strict orgs.

Methodology

Based on 20+ public sources: G2 reviews, Reddit and Hacker News threads, CVE databases, and official Typora pages.

Sources

  1. review
  2. review
  3. review
  4. review
  5. review
  6. official
  7. official
  8. security
  9. security
  10. security
  11. security
  12. news

Rate this review

Anonymous. You can change your vote.

Loading votes…

Comments

One queue. No nested comments. Give a display name first. Limit: 200 words per comment and 7 comments per day. You can edit or delete yours.

Save a name to write a comment.

0 / 200 words

No comments yet.