What is Caddy?

An open-source HTTP server that automatically enables and renews HTTPS certificates for all domains, provides flexible JSON-based configuration with adapters for other formats, and includes a fully-managed internal PKI system for securing internal services and clusters.

Independently observed

Caddy pricing

We don't have Caddy's full plan breakdown yet (its pricing page resisted automated reading). Here's what we could confirm. Always check live pricing for exact numbers.

Pricing as of verify at live pricing ↗Independently observed
Open sourceFree tier

Open source with optional paid commercial support through sponsorship tiers

Platform & deployment

Independently observed
Platforms
  • CLI
  • macOS
  • Linux
  • Windows
Deployment
  • Self-hosted

Integrations (14)

Independently observed
  • Cloudflare
  • Google Cloud DNS
  • TencentCloud DNS
  • Docker
  • Kubernetes
  • Consul
  • CrowdSec
  • Umami
  • Bunny CDN
  • OAuth 2.0
  • LDAP
  • OpenID Connect
  • SAML
  • Google Cloud KMS

Security & compliance

Known vulnerabilities: 7 (3 in the last 12 months), max severity CRITICAL sourcea count reflects scale & disclosure, not quality

Caddy alternatives

Other reverse proxies we track, ranked by the same independent score.

All Caddy alternatives, ranked →

Compare Caddy

Side by side against other reverse proxies, attribute by attribute, with a source on every value.

Independent · unbought · dated

The Vioscale score: one lens on the evidence

Not user reviews and not a paid placement: a confidence-weighted blend of the independent signals below (adoption, activity, security posture, and more), which you can sort and re-weight yourself. Vendors can correct their listing but can never move their rank, and stars are weighted low as a vanity metric. It is one way to read the evidence for Caddy, not the verdict.

Balanced composite 53 / 100
low · 38%updating
Signal contributions to the composite score
SignalScoreWeightContributionEvidence
Price level1000.055.2
Release cadence870.054.5
Development activity460.094.3
Security score920.043.9
Dependent projects560.063.5
Integrations340.093.2
Stars920.032.4
Pricing transparency250.082.1
Security posture250.071.8
Reliability00.070.0-
Capabilities00.080.0-
Package downloads00.140.0-
Developer Q&A activity00.060.0-

Computed . Re-weight it by intent, or see the full method.

All data & sourcesshow ↓

Every value we hold, with its source, retrieval date, and confidence. This is the evidence behind the score: don't trust it, verify it.

Activity

AttributeValueEvidence
Commits last 30d28mediumsource · 2026-08-26 · 65%

Adoption

AttributeValueEvidence
Github stars75,225highsource · 2026-08-26 · 90%
Dependent repos2,153highsource · 2026-08-26 · 85%

Integrations

AttributeValueEvidence
Count14mediumsource · 2026-08-19 · 60%

Language

AttributeValueEvidence
PrimaryGohighsource · 2026-08-26 · 90%

License

AttributeValueEvidence
SpdxApache-2.0highsource · 2026-08-26 · 95%

Pricing

AttributeValueEvidence
Free tierYesmediumsource · 2026-08-19 · 60%
Price levelfreemediumsource · 2026-08-19 · 60%
Modelcommerciallowsource · 2026-08-26 · 40%

Release

AttributeValueEvidence
Cadence days24mediumsource · 2026-08-26 · 70%
History20 itemsmediumsource · 2026-08-26 · 70%

Security

AttributeValueEvidence
HipaaYesmediumsource · 2026-08-19 · 60%
PciYesmediumsource · 2026-08-19 · 60%
Scorecard9.2highsource · 2026-08-26 · 90%
VulnerabilitiesCount: 7 · Source: https://advisories.ecosyste.ms/api/v1/advisories?ecosystem=go&package_name=github.com%2Fcaddyserver%2Fcaddy&per_page=100 · Last 12m: 3 · Max severity: CRITICALhighsource · 2026-08-26 · 90%