Tally Forms
Worth it
Confidence: High
Buy if you need polished, no-code forms for everyday collection . the free plan is genuinely unlimited and the Notion-style editor gets consistent top ratings.
Comparison
Tally Forms and Jotform both land on Worth it.
Buy if you need polished, no-code forms for everyday collection . the free plan is genuinely unlimited and the Notion-style editor gets consistent top ratings.
Buy if you need polished registration, application, or payment forms without code . the free plan covers light use well.
| Compare | Tally Forms | Jotform |
|---|---|---|
| Verdict | Worth it | Worth it |
| Best for | Solopreneurs, creators, and small teams who want good-looking forms without paying Typeform prices | Registration and application forms |
| Who it's not for | Anyone collecting sensitive or regulated data (health, financial, HR complaints): Tally disclosed a breach in August 2026 where a third-party Metabase analytics instance was exploited and customer emails plus password hashes were exposed. Do not point regulated data flows at it right now. | Basic surveys . Google Forms handles them free |
| Privacy | One significant known incident: in August 2026 Tally disclosed that an attacker exploited a Metabase SQL-injection zero-day (CVE-2026-0768) to access its analytics system, exposing customer email addresses and password hashes.⁹ | Core platform promotes a security program, VDP, and secure-form features; 2024 CVEs affect its WordPress plugin, and press references a past breach. |
| Public sentiment | Reviews are near-unanimous on one thing: the editor experience is exceptional and the free plan is genuinely generous . G2 sits at 4.9/5. | Across G2 and Reddit, users consistently praise Jotform as easy, fun, and user-friendly. |
| Biggest gotcha | Post-breach hygiene is on you: emails and password hashes were exposed in the Metabase breach. If you had an account, rotate the password and enable 2FA . and note hashed passwords were reported as properly protected.10 | Jotform Online Forms WordPress plugin (<=1.3.1) had stored XSS via shortcode . update immediately |