Immich
immich.appSelf-hostedSelf-hosted photo and video backup and management server, with automatic mobile upload, timeline view, albums, search and facial recognition. Needs to be self-hosted, but gives you full ownership + control over your photos.
- Homepage:immich.app
- GitHub:github.com/immich-app/immich
- iOS App:apps.apple.com/us/app/immich/id1613945652
- Android App:play.google.com/.../app.alextran.immich
- Discord:cHD2af9DbA
- Subreddit:r/immich
- Web info:web-check.xyz/check/immich.app
Immich Source Code
Author
Description
High performance self-hosted photo and video management solution.
Homepage
https://immich.appRepository
- LicenseAGPL-3.0
- Created03 Feb 22
- Primary languageTypeScript
- Size324,132 KB
- Stars113,345
- Forks6,809
- Watchers113,345
Top Contributors
@alextran1502 (1964)
@jrasm91 (1372)
@renovate[bot] (1198)
@shenlong-tanwen (504)
@mertalev (465)
@danieldietzler (443)
@michelheusschen (355)
@bo0tzz (334)
@zackpollard (201)
@midzelis (197)
@martabal (170)
@bwees (139)
@YarosMallorca (131)
@mmomjian (129)
@github-actions[bot] (117)
@etnoy (116)
@weblate (105)
@dependabot[bot] (95)
@meesfrensel (91)
@martyfuhry (91)
@timonrieger (85)
@uhthomas (83)
@fyfrey (76)
@wuzihao051119 (61)
@santoshakil (61)
@matthinc (59)
@benmccann (58)
@Snowknight26 (51)
@ben-basten (51)
@waclaw66 (46)
@agg23 (46)
@aviv926 (38)
@zoodyy (34)
@LeLunZ (32)
@brighteyed (29)
@NicholasFlamy (29)
@skatsubo (27)
@benbeckford (25)
@jbaez (25)
@xCJPECKOVERx (25)
@samip5 (23)
@panoti (20)
@lukashass (19)
@idubnori (19)
@adamantike (17)
@faupau03 (16)
@immich-tofu[bot] (16)
@daniele-athome (15)
@C-Otto (15)
@goalie2002 (13)
@ddshd (12)
@insertish (12)
@PeterOmbodi (12)
@arnolicious (12)
@dvbthien (12)
@JobiJoba (11)
@Saschl (11)
@lukasdotcom (11)
@roschaefer (10)
@Lauritz-Tieste (10)
@Ethan13310 (10)
@tech00exploere (9)
@dagstuan (9)
@cratoo (8)
@JW-CH (8)
@MontejoJorge (8)
@savely-krasovsky (8)
@stewx (8)
@Mraedis (8)
@dotlambda (8)
@ConnerWithAnE (7)
@okxint (7)
@bt90 (7)
@Wingysam (7)
@mPyKen (7)
@johnstef99 (7)
@Funk66 (7)
@ferraridamiano (7)
@Yuvi-raj-P (6)
@thariq-shanavas (6)
@sellnat77 (6)
@klejejs (6)
@JordyEGNL (6)
@jonhnet (6)
@fredfloydd (6)
@rovo89 (5)
@xpwmaosldk (5)
@luzpaz (5)
@indam (5)
@debricked[bot] (5)
@zkhan93 (5)
@Tushar-Harsora (5)
@EinToni (5)
@atollk (5)
@eligao (5)
@jinxuan-owyong (5)
@PixelJonas (5)
@Tyris (5)
@dahool (5)
@RanKKI (5)
Recent Commits
bo0tzz(03 Sept 26)
feat: new FAQ entries (#31227) * feat: new FAQ entries * chore: fix formatting * add suggestion * nit: wording --------- Co-authored-by: github-actions <41898282+github-actions[bot]@users.noreply.github.com>
Adam Gastineau(03 Sept 26)
fix(mobile): use timeline scroll velocity to add placeholders (#29443) * fix(mobile): use timeline scroll velocity to add placeholders * Switch to using Flutter recommendDeferredLoading * Shared debounce logic
Yohanes Kirana(03 Sept 26)
fix(web): partner sharing timeline (#31241) * fix(web): prevent websocket assets from leaking into scoped timelines * test: add 1 more test case to make sure the changes didnt break the logic
Adam Gastineau(03 Sept 26)
fix(mobile): prevent inner mutability on Freezed classes (#31229) * fix(mobile): prevent inner mutability on Freezed classes * Minor fixes
Adam Gastineau(03 Sept 26)
chore(ci): run mobile jobs when OpenAPI defs change (#31245) Co-authored-by: shenlong <[email protected]>
Adam Gastineau(03 Sept 26)
fix(mobile): switch to new OpenAPI int in RotateParameters (#31246)
Daniel Dietzler(03 Sept 26)
fix: face detection of edited assets (#31240)
Mees Frensel(03 Sept 26)
fix(web): album date range formatting (#28564)
Wenbin(03 Sept 26)
fix(ml): race when submitting to rknn execution queue (#31143)
Alex(02 Sept 26)
fix: incorrect edit's openapi type (#31218) * fix: incorrect edit's openapi type * patch * remove type changes
bo0tzz(02 Sept 26)
fix: don't force builds on release-base PRs (#31225)
Jason Rasmussen(02 Sept 26)
chore: require number format (#31222)
Jason Rasmussen(02 Sept 26)
fix: fdroid link (#31219)
Santo Shakil(02 Sept 26)
chore(mobile): log app resume and pause (#31207)
shenlong(01 Sept 26)
chore: asset page zoom test overrides (#31201) Co-authored-by: shenlong-tanwen <[email protected]>
Jason Rasmussen(01 Sept 26)
chore: add backport label to backported prs (#31195)
Aditya Raj Singh(01 Sept 26)
fix(server): never unlink an untracked-file path that an asset now references (#31074)
bo0tzz(01 Sept 26)
fix: add discussions perm to release publish token (#31167)
Alex(01 Sept 26)
chore: remove stars chart from readme (#31175)
bo0tzz(01 Sept 26)
fix: workflows write perm on backport job (#31191)
Matthew Momjian(01 Sept 26)
chore(docs): deprecate outlook SMTP (#31139) deprecation warning
renovate[bot](01 Sept 26)
chore(deps): update github-actions (#31182) Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
renovate[bot](01 Sept 26)
chore(deps): update ghcr.io/jdx/mise docker tag to v2026.8.16 (#31177)
renovate[bot](01 Sept 26)
chore(deps): update typescript-projects (#31183) Co-authored-by: Daniel Dietzler <[email protected]>
bo0tzz(31 Aug 26)
fix: open an announcement discussion for each release line (#31101)
Alex(31 Aug 26)
fix(web): interaction with some filter elements closes the search panel (#31107)
Ray(31 Aug 26)
fix: Build SDK in dev container (#31096)
Ufuk(31 Aug 26)
fix(server): allow an empty assetIds array when creating an album shared link (#31098)
Daniel Dietzler(31 Aug 26)
fix: do not move faces of users other than the current owner (#31145)
Santo Shakil(31 Aug 26)
fix(mobile): refresh server info when the websocket connects (#31144) refresh the server features and config when the websocket connects
Immich Security
Security Advisories (12)
- lowPatched
GHSA-h5w4-vjv4-9r5qIncorrect sanitization of continue URL on the /maintenance endpoint
- mediumPatchedCVSS 6.1
GHSA-qp2h-w794-2vhfIncomplete fix for login continue redirect allows slash-backslash open redirect
- criticalPatchedCVSS 9.6
CVE-2026-53662One-click account takeover via XSS in login page continue redirect
- mediumPatchedCVSS 4.7
GHSA-hfvf-5c8x-8rc4OIDC discovery/token/userinfo/JWKS fetches run with TLS certificate verification unconditionally disabled via allowInsecureRequests (CWE-295)
- mediumPatched
CVE-2026-40096Open Redirect via Shared Album name
- lowPatchedCVSS 2.8
GHSA-jrp5-g662-hq92Unsafe ZIP Entry Names (Zip Slip Class) in Archive Download Endpoint
- highPatchedCVSS 7.3
CVE-2026-35455Stored XSS via OCR Text in 360° Panorama Viewer
- mediumPatchedCVSS 4.1
GHSA-hq46-gw2v-q86pSSRF via OAuth Profile Picture URL (CWE-918)
- highPatchedCVSS 7.2
CVE-2026-23896API Key Privilege Escalation
- mediumPatched
GHSA-hvq7-hq9r-8gjr[DCODX-AI] Shared-link authentication allows adding owner's assets to shared links (AssetShare authorization bypass)
- mediumPatched
CVE-2026-25118Insecure transmission of shared link password
- highPatched
CVE-2025-43856Account hijacking through oauth2
Immich Website
Website
Immich
Self-hosted photo and video management solution. Easily back up, organize, and manage your photos on your own server. Immich helps you browse, search and organize your photos and videos with ease, without sacrificing your privacy.
Redirects
Does not redirect
Security Checks
All 65 security checks passed
Server Details
- IP Address172.67.129.142
- LocationSan Francisco,California,United States of America,NA
- ISPCloudFlare Inc.
- ASNAS13335
Associated Countries
US
Safety Score
Website marked as safe
100%
Blacklist Check
immich.app was found on 0 blacklists
- AntiSocial Blacklist
- Artists Against 419
- Badbitcoin
- Bambenek Consulting
- CERT Polska
- CoinBlockerLists
- CRDF
- CryptoScamDB
- EtherAddressLookup
- EtherScamDB
- Fake Website Buster
- MetaMask EthPhishing
- NABP Not Recommended Sites
- OpenPhish
- PetScams
- PhishFeed
- PhishFort
- Phishing.Database
- PhishStats
- PhishTank
- Phishunt
- RPiList Not Serious
- Scam.Directory
- SecureReload Phishing List
- Spam404
- StopGunScams
- Suspicious Hosting IP
- ThreatFox
- ThreatLog
- TweetFeed
- URLhaus
- ViriBack C2 Tracker
Website Preview
Immich Android App
APK Info
- AppImmich
- Creation Date18 May 24
- Last Updated14 Jul 24
- Current Version1.104.0
- Privacy ReportView on Exodus →
De-Googled Compatibility
- GrapheneOSNative4.0 / 4(16)
- crDroidmicroG4.0 / 4(4)
- LineageOSNative4.0 / 4(3)
- Evolution XNative4.0 / 4(2)
- LineageOSmicroG4.0 / 4(2)
- CalyxOSmicroG4.0 / 4(2)
Trackers
No trackers found
Permissions
- Access Coarse Location
- Access Fine Location
- Access Media Location
- Access Network State
- Access Wifi State
- Foreground Service
- Internet
- Manage Media
- Post Notifications
- Read External Storage
- Read Media Audio
- Read Media Images
- Read Media Video
- Receive Boot Completed
- Vibrate
- Wake Lock
- Write External Storage
- Dynamic Receiver Not Exported Permission
Immich iOS App
App Info
Immich
This is a client app for Immich Server and you will need to run/manage the server on your own in order to use the app. Website: https://immich.app GitHub: https://github.com/immich-app/immich
Rating
Version Info
- Current Versionv3.1.0
- Last Updated29 Jul 26
- First Released12 Mar 22
- Minimum iOS Version15.0
- Device Models Supported127
App Details
- IPA Size74.08 Mb
- PriceFree (USD)
- Age Advisory4+
- Supported Languages1
- DeveloperFUTO Holdings, Inc.
- Bundle IDapp.alextran.immich
Screenshots
Immich Docker
Container Info
immich
Immich is a high performance self-hosted photo and video backup solution.
Run Command
docker run -d \
Compose File
version: 3.8
Immich Socials
Immich Reviews
More Photo Management
Provides an open source, audited end-to-end encrypted platform to store photos in the cloud without needing to trust the service provider. With apps for desktop, web and mobile, album sharing, public links, semantic search and facial recognition. Self-hosted or 10GB free.
About the Data: Immich
Change History
- Added #621
Edit Immich Data
You can edit Immich's entry in this section of awesome-privacy.yml by submitting a PR to our GitHub repo.
Note that some of the information shown above has been aggregated from external
sources, a list of these can be found data documentation.
Origin Data
Modify Data
API
You can access Immich's data programmatically via our API. Simply make a GET request to:
https://api.awesome-privacy.xyz/v1/services/immichThe REST API is free, no-auth and CORS-enabled. To learn more, view the API Docs or read the API Usage Guide.
Share Immich
Help your friends compare Photo Management, and pick privacy-respecting software and services.
Share Immich and Awesome Privacy with your network!
