Joplin

joplinapp.org
Joplin

Cross-platform desktop and mobile note-taking and todo app. Easy organisation into notebooks and sections, revision history and a simple UI. Allows for easy import and export of notes to or from other services. Supports synchronisation with cloud services, implemented with E2EE.

Security Audited Open Source

Joplin Privacy Policy

Privacy Policy Summary

  • You can delete your content from this service

Score

C

Documents

About the Data

This data is kindly provided by tosdr.org. Read full report at: #9477

Joplin Source Code

Author

laurent22

Description

Joplin - the privacy-focused note taking app with sync capabilities for Windows, macOS, Linux, Android and iOS.

#android#dropbox#electron#enex-files#evernote#javascript#joplin#nextcloud#nodejs#note-taking#notesnook#obsidian#onedrive#react-native#standardnotes#synchronisation#web-clipper#webdav

Homepage

https://joplinapp.org

Repository

  • LicenseOther
  • Created16 Jan 17
  • Primary languageTypeScript
  • Size659,401 KB
  • Stars56,228
  • Forks6,260
  • Watchers56,228

Language Usage

Language Usage

Project Health

  • Last commit5 days ago
  • Open issues643
  • Latest releasev3.7.14

Recent Commits

  • renovate[bot](03 Sept 26)

    fix(deps): update dependency react-native-zip-archive to v7.1.1 (#16387) Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>

  • renovate[bot](03 Sept 26)

    fix(deps): update dependency @react-native-community/netinfo to v12 (#16388) Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>

  • Laurent Cozic(03 Sept 26)

    Server: Improve logging for shared notebook maintenance (#16400)

  • ERYpTION(02 Sept 26)

    All: Translation: Update da_DK.po (#16380)

  • renovate[bot](01 Sept 26)

    fix(deps): update dependency node-diff3 to v3.2.1 (#16376) Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>

  • renovate[bot](01 Sept 26)

    fix(deps): update dependency dompurify to v3.4.8 (#16373) Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>

  • Joplin Bot(01 Sept 26)

    Doc: Auto-update documentation Auto-updated using release-website.sh

  • renovate[bot](01 Sept 26)

    chore(deps): update eslint (#16365) Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>

  • Laurent Cozic(01 Sept 26)

    Merge branch 'release-3.7' into dev

  • Laurent Cozic(01 Sept 26)

    Update translations

  • Laurent Cozic(01 Sept 26)

    Update translations

  • Joplin Bot(31 Aug 26)

    Doc: Auto-update documentation Auto-updated using release-website.sh

  • Laurent Cozic(31 Aug 26)

    Doc: Add release notes 3.7 (#16360)

  • renovate[bot](30 Aug 26)

    fix(deps): update dependency tar to v7.5.16 (#16356) Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>

  • Joplin Bot(30 Aug 26)

    Doc: Auto-update documentation Auto-updated using release-website.sh

  • Laurent Cozic(30 Aug 26)

    Merge branch 'release-3.7' into dev

  • Laurent Cozic(30 Aug 26)

    Desktop release v3.7.14

  • Henry Heino(30 Aug 26)

    Desktop: Resolves #16350: External editor: Add additional logic to avoid overwriting a note with older content (#16352)

  • mrjo118(30 Aug 26)

    Desktop: Fixes #16059: Stop external editing on note deletion (#16355)

  • renovate[bot](29 Aug 26)

    fix(deps): update dependency onnxruntime-node to v1.25.1 (#16338) Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>

  • renovate[bot](29 Aug 26)

    fix(deps): update dependency tar-stream to v3.2.0 (#16332) Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>

  • renovate[bot](29 Aug 26)

    chore(deps): update dependency yauzl to v3.3.2 (#16351) Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>

  • Joplin Bot(28 Aug 26)

    Doc: Auto-update documentation Auto-updated using release-website.sh

  • Laurent Cozic(28 Aug 26)

    iOS 13.7.3

  • Laurent Cozic(28 Aug 26)

    Android 3.7.7

  • Laurent Cozic(28 Aug 26)

    Desktop release v3.7.13

  • Henry Heino(28 Aug 26)

    Chore: Tests: Silence expected handleCallbackUrl warnings (#16343)

  • Aissa Benfodda(28 Aug 26)

    Desktop, Cli: Resolves #15223: Add support to import notes from Obsidian (#16136)

  • renovate[bot](28 Aug 26)

    chore(deps): update dependency @rollup/plugin-commonjs to v29.0.3 (#16331) Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>

  • Henry Heino(28 Aug 26)

    Desktop: Fixes #15890: Limit maximum size of stored OCR text (#16325)

Joplin Security

4.6/10

Repo Security Summary

Updated 24 Aug 26

  • Code-Review4/10
  • Maintained10/10
  • PackagingN/A
  • CII-Best-Practices0/10
  • Dangerous-Workflow10/10
  • Security-Policy10/10
  • Token-Permissions0/10
  • License9/10
  • Branch-ProtectionN/A
  • Signed-Releases0/10
  • Binary-Artifacts7/10
  • SAST0/10
  • Pinned-Dependencies0/10
  • Fuzzing0/10

Security Advisories (15)

  • mediumPatchedCVSS 5.7

    CVE-2026-34600Logic error in Joplin Server allows share recipients to read notes they no longer have access to

  • highPatchedCVSS 8.2

    CVE-2026-22810Path traversal in OneNote importer allows overwriting arbitrary files

  • mediumPatchedCVSS 5.5

    CVE-2025-57798Denial of Service (DoS) via Uncontrolled Resource Allocation in Joplin Title Input

  • highPatchedCVSS 7.5

    CVE-2025-27409Path traversal in Joplin Server

  • highPatchedCVSS 8.8

    CVE-2025-27134Privilege escalation in Joplin server via user patch endpoint

  • highUnpatchedCVSS 7.8

    CVE-2025-24028XSS in Rich Text Editor allows arbitrary code execution

  • lowPatchedCVSS 3.3

    CVE-2024-55630DOM Clobbering leads to temporary DOS in the note viewer

  • highPatchedCVSS 7.2

    CVE-2024-53268Lack of validation on openExternal allows XSS

  • highPatchedCVSS 7.8

    CVE-2025-25187XSS in Goto Anything allows arbitrary code execution

  • highPatchedCVSS 7.7

    CVE-2024-49362XSS on <a> Link in markdown preview

  • highPatchedCVSS 8.6

    CVE-2024-40643Parsing error leading to XSS

  • highPatchedCVSS 8.1

    CVE-2023-45673Arbitrary code execution on click of PDF links

  • highPatchedCVSS 7.3

    CVE-2023-39517XSS when clicking on an untrusted `<map>` link

  • highPatchedCVSS 7.3

    CVE-2023-38506XSS when pasting HTML into the rich text editor

  • highPatchedCVSS 7.3

    CVE-2023-37898Safe mode XSS vulnerability

Joplin Website

Website

Joplin

Joplin, the open source note-taking application

Redirects

Does not redirect

Security Checks

All 65 security checks passed

Server Details

  • IP Address185.199.110.153
  • Hostnamecdn-185-199-110-153.github.com
  • LocationFrancisco,Indiana,United States of America,NA
  • ISPGitHub Inc.
  • ASNAS54113

Associated Countries

  • FRFR
  • USUS

Safety Score

Website marked as safe

100%

Blacklist Check

joplinapp.org was found on 0 blacklists

  • AntiSocial Blacklist
  • Artists Against 419
  • Badbitcoin
  • Bambenek Consulting
  • CERT Polska
  • CoinBlockerLists
  • CRDF
  • CryptoScamDB
  • EtherAddressLookup
  • EtherScamDB
  • Fake Website Buster
  • MetaMask EthPhishing
  • NABP Not Recommended Sites
  • OpenPhish
  • PetScams
  • PhishFeed
  • PhishFort
  • Phishing.Database
  • PhishStats
  • PhishTank
  • Phishunt
  • RPiList Not Serious
  • Scam.Directory
  • SecureReload Phishing List
  • Spam404
  • StopGunScams
  • Suspicious Hosting IP
  • ThreatFox
  • ThreatLog
  • TweetFeed
  • URLhaus
  • ViriBack C2 Tracker

Website Preview

Website preview

Joplin Android App

APK Info

De-Googled Compatibility

Native4.00/ 49 ratings
microG4.00/ 46 ratings
  • GrapheneOSNative4.0 / 4(6)
  • iodeOSmicroG4.0 / 4(2)
  • LineageOSNative4.0 / 4(2)
  • CalyxOSmicroG4.0 / 4(2)

Tested on Android 14–16 · Updated 06 Sept 26 · View on Plexus →

Trackers

No trackers found

    Permissions

    • Access Fine Location
    • Access Network State
    • Access Wifi State
    • Internet
    • Post Notifications
    • Read External Storage
    • Read Media Images
    • Receive Boot Completed
    • Record Audio
    • Use Biometric
    • Use Fingerprint
    • Vibrate
    • Wake Lock
    • Write External Storage
    • Access Fingerprint Manager
    • Write Use App Feature Survey

    Joplin iOS App

    App Info

    Joplin

    Privacy-first app Capture your thoughts freely and without distractions, tracking, or ads. With Joplin’s end-to-end encryption and open-source code, you can concentrate on your ideas and tasks without worrying about your privacy. Capture multimedia notes Capture multimedia notes effortlessly. In Joplin you can : • create manuscript notes, • transcribe speech to note, • add multimedia: photos, videos, PDFs, and images, • insert documents as attachments, • create math expressions, add tables, write code and insert diagrams, • create to-dos and add reminders. Organise your ideas Organise your notes into notebooks. Connect your notes with tags by subject or priority. Use colours and rich text editor to format your notes with ease. Make task lists, create to-dos and add reminders. Effortlessly find your notes, even within PDFs and images, thanks to the powerful search feature enhanced by Optical Character Recognition (OCR) technology. Use Joplin to store your bills, lecture notes, photos or receipts. Reliable synchronisation Access your notes from computer, phone or tablet by synchronising with various services including Joplin Cloud, Dropbox and OneDrive. Seamlessly move from one device to another. Offline-first You can access your notes anytime and anywhere, even without Internet. If you’re using Joplin on multiple devices, they will synchronise and update once you regained the connection. Enhance your productivity across devices Extend your note-taking experience by using Joplin on additional devices such as a desktop computer or tablet. Make the most of each device by using its specific features. On the desktop app, use a web clipper extension, wide-range of community plugins and a Markdown editor. Experience flawless handwriting and drawing on your tablet. Join active community Connect with Joplin’s vibrant community on Joplin Forum. It’s a place where users can share ideas, ask questions, exchange information and give feedback. Joplin’s dynamic community also develops powerful plugins, so you can customise your app to suit your needs.

    Rating

    Rated 4.14 out of 5 stars by 473 users

    Version Info

    • Current Version13.7.4
    • Last Updated05 Sept 26
    • First Released21 Nov 17
    • Minimum iOS Version15.6
    • Device Models Supported127

    App Details

    • IPA Size72.62 Mb
    • PriceFree (USD)
    • Age Advisory4+
    • Supported Languages1
    • DeveloperLaurent Cozic
    • Bundle IDnet.cozic.joplin

    Screenshots

    • App screenshot

    Joplin Docker

    Container Info

    Joplin

    [Joplin](https://joplinapp.org/) is a free, open source note taking and to-do application, which can handle a large number of notes organised into notebooks.

    #Content Management

    View on DockerHub

    linuxserver/joplin:latest

    Run Command

    docker run -d \
      -p 3000:3000/tcp \
      -p 3001:3001/tcp \
      -e PUID=${PUID} \
      -e PGID=${PGID} \
      -e TZ=${TZ} \
      -v /srv/lsio/joplin/config:/config \
      --restart=unless-stopped \
      linuxserver/joplin:latest

    Compose File

    version: 3.8
    services:
      joplin:
        image: "linuxserver/joplin:latest"
        ports:
          - "3000:3000/tcp"
          - "3001:3001/tcp"
        environment:
          PUID: 1000
          PGID: 1000
          TZ: Etc/UTC
        volumes:
          - "/srv/lsio/joplin/config:/config"
        restart: unless-stopped

    Environment Variables

    • Var NameDefault
    • PUID1000
    • PGID1000
    • TZEtc/UTC

    Port List

    • 3000:3000/tcp
    • 3001:3001/tcp

    Volume Mounting

    • Container PathHost Bind
    • /config/srv/lsio/joplin/config

    Joplin Reviews

    More Digital Notes

    • Cryptee

      Cryptee

      crypt.ee

      Private & encrypted rich-text documents. Cryptee has encryption and anonymity at its core, it also has a beautiful and minimalistic UI. You can use Cryptee from the browser, or download native apps. Comes with many additional features, such as support for photo albums and file storage. The disadvantage is that only the frontend is open source. Pricing is free for starter plan, $3/ month for 10GB, additional plans go up-to 2TB.

      No Security AuditNot Open Source cryptee/web-client
    • Logseq

      Logseq

      logseq.com

      Privacy-first, open-source knowledge base that works on top of local plain-text Markdown and Org-mode files. Supports lots of different note modes, including task management, PDF annotation, flashcards, whiteboards strong markdown support and more. Includes themes and extensions, backed by a strong community

      No Security Audit Open Source logseq/logseq
    • Notable

      Notable

      notable.md

      An offline markdown-based note editor for desktop, with a simple, yet feature-rich UI. All notes are saved individually as .md files, making them easy to manage. No mobile app, built-in cloud-sync, encryption or web UI. But due to the structure of the files, it is easy to use your own cloud sync provider, and additional features are provided through extensions.

      No Security Audit Open Source notable/notable
    • Obsidian

      Obsidian

      obsidian.md

      A powerful knowledge base that works on top of local plain-text Markdown files. It has a strong community, and a lot of plugins and themes. Generally privacy-respecting, but no encryption out of the box, and some of the code is obfuscated or not fully open source

    • Poznote

      Poznote

      poznote.com

      Self-hosted notes and tasks app with rich-text, Markdown and drawing editors, tags, multi-user, OIDC login and a REST API. Docker-based (PHP + SQLite); the only outbound call is a daily update check. No mobile apps (PWA), no end-to-end encryption.

      No Security Audit Open Source timothepoznanski/poznote
    • Standard Notes

      Standard Notes

      standardnotes.com

      S.Notes is a free, open-source, and completely encrypted private notes app. It has a simple UI, yet packs in a lot of features, thanks to the Extensions Store, allowing for: To-Do lists, Spreadsheets, Rich Text, Markdown, Math Editor, Code Editor and many more. You can choose between a number of themes (yay, dark mode!), and it features built-in secure file store, tags/ folders, fast search and more. Standard Notes is actively developed, and fully open-source.

    • Turtle

      Turtle

      turtlapp.com

      A secure, collaborative notebook. Self-host it yourself, or use their hosted plan (free edition or $3/ month for premium).

      Security Audited Open Source turtl/desktop
    • VNote

      VNote

      app.vnote.fun/en_us

      A free, open-source note-taking application built with Qt, focused on providing a pleasant Markdown editing experience. It manages notes directly as plain text files on your local system.

    About the Data: Joplin

    Change History

    • Amended (androidApp, iosApp, subreddit)

    Edit Joplin Data

    You can edit Joplin's entry in this section of awesome-privacy.yml by submitting a PR to our GitHub repo.
    Note that some of the information shown above has been aggregated from external sources, a list of these can be found data documentation.

    Origin Data

    Modify Data

    API

    You can access Joplin's data programmatically via our API. Simply make a GET request to:

    https://api.awesome-privacy.xyz/v1/services/joplin

    The REST API is free, no-auth and CORS-enabled. To learn more, view the API Docs or read the API Usage Guide.

    Share Joplin

    Help your friends compare Digital Notes, and pick privacy-respecting software and services.
    Share Joplin and Awesome Privacy with your network!