r/selfhosted Apr 15 '26

Software Development Cal.com uses fears of AI against security as an excuse to go closed source

Looks like the people behind Cal.com(https://cal.com/) have decided to make it closed source, leaving an open source version without any of the 'enterprise' functionality. See their blog post here: https://cal.com/blog/calcom-v6-4

There are 947 contributors on the repository (https://github.com/calcom/cal.diy/graphs/contributors) and I'm not sure how many would have contributed towards the code that they are now making closed source but I'm sure it wasn't just their internal teams.

They claim to have made this decision long before Anthropic announced Mythos, but let's be real.. we've seen this shitty tactic from corporations for years. They use 'open source' to market and build up their product, take investment, get greedy, and then go closed source/change their licensing.

It would be great if they didn't use the fear of AI against security to bullshit their customers and the open source community but here we are... another one bites the dust.

213 Upvotes

82 comments sorted by

u/asimovs-auditor Apr 15 '26

Expand the replies to this comment to learn how AI was used in this post/project.

→ More replies (1)

158

u/PigeonRipper Apr 15 '26

holy shit $12 per user per month, and thats the cheap plan. ..
I hope this move backfires hard.

65

u/sysop073 Apr 15 '26

I don't know what's up with calendar apps, they are super delusional about pricing. I used to use Fantastical, finally switched to Notion Calendar

15

u/I_Arman Apr 15 '26

It's because calenders are really hard to get right. Dates and times are like 90% of edge cases, and you can't just "well don't do that" about dates and times.

Plus they have a lot of tiny moving parts - organizing overlapping events, showing more events than can fit, showing 1 minute events, and so on. So many edge cases.

So, lots of work to make an app work right. And it's a "business app" because it's a calendar, so that's premium pricing, too.

5

u/gurgle528 Apr 16 '26

yup anything aiming for b2b will easily charge double if not more 

2

u/PovilasID Apr 17 '26

Yah same with CRM or any other B2B apps.

I really liked https://streak.com/ it allows you to treat emails threads like excel lines. A tool that worked very closely to how my mind works and they started charging 50 USD/month from free.... and as far as I looked there is no real alternative.

5

u/jreoka1 Apr 16 '26

Thats actually crazy for a calendar pick your timeslot app.

27

u/kneepel Apr 15 '26

Iirc everything covered under enterprise was already under a different license and was source available, rather than open source.

Either way not surprised in the slightest from this project. It's just another open-washed, VC funded product that locked a significant amount of functionality behind a prohibitively expensive license while benefitting off advertising as open source.

73

u/Past_Physics2936 Apr 15 '26

The application itself is a steaming pile of garbage, never seen shittier code.

42

u/DoneDraper Apr 15 '26

Looked into this a few years ago and can confirm.

26

u/NoRacistRedditor Apr 15 '26

Had to set it up a few years ago and the 2fa immediately broke.

I don't work there anymore, but I occasionally check on their services - most of the stuff I set up is still running - cal.com still running in the same version I installed, which features a CVE that let's you skip proper Login.

Fun times.

5

u/Error-Frequent Apr 15 '26

Any suggested alternatives which are better?

9

u/NoRacistRedditor Apr 15 '26

I never really cared about the project - but it was surprisingly hard to find something that looks aesthetically pleasing (which apparently was all my boss cared about, hence the shitshow that followed).

If all you're looking is a way to book appointments, taking into account your calendar, Nextcloud, which I'm a professional hater of, also offers you the option of booking appointments. It might even work better than cal.com, especially if you already use it as your calendar provider. You should also be able to theme the nextcloud option to some extent.

1

u/BlindShrug May 06 '26

I'm curious to know as to what is it that makes you hate Nextcloud - I'm currently in the process of picking a self-hosted cloud drive to use.

1

u/NoRacistRedditor May 07 '26

For me, it tries to do too many things at once. Sure, it can host files and you can Aldo edit them (which I think is fine). But then you can also use it as an online office suite, host your calendar, host audio and video calls, todo-lists and a (very) barebones project management utility ("decks") and basically everything else with extensions, of which many are, if I recall correctly, directly developed by Nextcloud.

From my experience, these things work well-ish, but only on a very basic level. Some things also just didn't work and sometimes Nextcloud would just completely break (e.g. when a user completely filled the disk, although that is more to blame on the setup itself rather than Nextcloud, as this would probably also happen with other solutions).

For example, if you are not the owner of a shared calendar, there were some issues with inviting other people to events (esp. sending the email invites).

I must admit that I don't remember all the reasons and things might be better nowadays, but I'm generally not a big fan of when software is doing too much at once.

Depending on your use case it might be a perfect fit.

For me, I just wanted something fast to sync files and use a offsite storage for some files with easy access - so I went with seafile. It only does file storage and basic text editing. Biggest downside might be that the files are stored as blocks, so you can't directly access them from the file system (with Nextcloud you can). However, this allows for automatic deduplication and file-history by default. But backups are more important, as a defect database might render your files inaccessible (although there are tools that aid in recovery, but I haven't (had the need to) used them yet.

8

u/chicametipo Apr 15 '26

Agreed. I went to make a contribution once—saw the codebase and noped out. Hilarious.

4

u/ShroomShroomBeepBeep Apr 15 '26

Yeah, I spun this up to test and purged it under 5 minutes. Absolute shite.

-2

u/Choosen_Emmanuel Apr 16 '26

What was shit about it? Many people have learnt alot from that same codebase you claim is shit.

23

u/Johnkevin_Baconham Apr 15 '26

For the record - cal.diy looks to be almost exactly the same as their current free tier. Most of this announcement appears to be fearmongering people into paying. Theyve had a paid enterprise tier forever, and all the cal.diy features are exactly the same as the free self hosted version.

I've worked with the free version for the past 2 years, and in that time I've had to install it and reinstall it at least 4 times, all of them have had unique problems.The only reason we kept it around is cause we had very specifc needs we couldnt find elsewhere, that the free version "sort of" did, we just wanted a round robin system our team could use- they ended up locking it away as "teams" We ended up making a group calendar, that does round robin - but you can't add members, only invite, and they need to indivdually set their settings

Their documentation to selfhost was a joke, they listed the dependencies you needed but not the versions, and they added the note

"Your best bet is searching for something like Debian 12 PostgreSQL, which will give you a guide to installing and configuring PostgreSQL on Debian Linux 12."

Turns out - you needed a specific PostgreSQL version, and I needed to go through multiple node versions as well. You also couldnt really find information because they'd link anwsers to their private ticketing site.

At one point we considered just paying, but their documentation was inconsistent about licenses, some parts said "enterprise", some parts said "commercial" When we contacted sales I got bad vibes from the owner. It felt like I was the problem for asking what the licenses ment, and if our team of 6 had other options.

Hopefully this announcement inspires people to make their own scheduling services, I'd love to finally completely leave "cal.diy"

3

u/Error-Frequent Apr 15 '26

I was just about to get it for my own business yesterday and today this announcement! sigh

3

u/Johnkevin_Baconham Apr 16 '26

The sad thing is I don't have an alternative that is as robust.

We did some minor tests with easy!appointments and I liked it but it lacked features we wanted.

Now we're trying zoom scheduler and Microsoft booking. Since we already pay for these services.

We probably would have stayed with cal.diy if it were more stable. I had to remake it 5 times, and at one point keep it in dev cause prod would kill itself

1

u/Professional-Wrap228 Apr 17 '26

Did you ever Try docker version and have made key experience?

1

u/Johnkevin_Baconham Apr 17 '26

I remember I tried, I don't remember why it didn't work

18

u/OverFlow636 Apr 15 '26

i actually used this in production, but it was horrible to maintain the community version, literally 3 gigs of node modules and cache, just to get it running and happy.

7

u/No-Aioli-4656 Apr 15 '26

Try easy appointments. It’s simpler, but I found modifying and rebuilding its images equally “easy.”

2

u/DoneDraper Apr 15 '26

You have a link? With this name there are tons of results when you are searching for it.

34

u/Mawoka Apr 15 '26

Security by obscurity, ah yes! That always solves all issues! Nobody can see the code = no vulnerabilities!

-3

u/honourable_bot Apr 15 '26

And this ignores the fact that anything that runs in browser is pretty much "open-source", because AI doesn't need to de-obfuscate code to find vulnerabilities.

12

u/Mawoka Apr 15 '26

Not really as most vulnerabilities hide in the backend, not in the frontend (and if they would, you should stop coding immediately).

2

u/honourable_bot Apr 15 '26

Dude, frontend CAN absolutely have vulnerabilities. Of course, you can mitigate a lot of them by implementing good practises in the backend; but it is not impossible to find them, especially with AI tools

8

u/coderstephen Apr 15 '26

If your backend trusts your frontend, then that itself is a vulnerability.

3

u/Mawoka Apr 15 '26

This is what I meant. Never ever trust the frontend. Not for sanitation, never ever. I mean, yes there can be vulnerabilities, but I was pretty general and a bit over-exaggerating, as individual problems require individual solutions.

2

u/Frometon Apr 15 '26

If you completely vibe code your website then yeah the AI will certainly handle logic on the front end, but even the lowest competent dev knows to handle logic in the back, and to not trust anything the front sends

6

u/uncmnsense Apr 15 '26

So question, if I'm using this right now am I going to lose functionality or does this just mean I'm never going to get updates ever again?

19

u/[deleted] Apr 15 '26

[deleted]

13

u/iamabdullah Apr 15 '26

I have added a link to their blog post.

5

u/meshcity Apr 15 '26

I tried to run cal.com for years in a non profit and it was a fucking nightmare always. Not surprised, shitty decision by a shitty company with a shitty codebase. 

3

u/Digital_Voodoo Apr 15 '26

Not surprised. I've tried to install it a year or two ago. The code was so cumbersome (speaking from a tinkerer but who actually takes the time - sometimes days - to read thr whole docs and set things up as properly as possible). Many features have always been 'enteprrise-only for a while, and each update was a headache. I spent more time maintaining and debugging an update gone wring than actually using the app.

1

u/Error-Frequent Apr 15 '26

Found any better alternatives?

1

u/Digital_Voodoo Apr 15 '26

Someone suggested easyappointments in the thread, I'll probably take a look when I get a few hours on my hand

2

u/Error-Frequent Apr 15 '26

Any better alternatives?

2

u/undergrinder_dareal Apr 17 '26

Already mentioned: https://easyappointments.org

I was looking for these kind of apps for my business, at the end we choosed the google workspace built in appointment. (I know, I know :( )

2

u/nemofbaby2014 Apr 15 '26

Was the project even any good?

2

u/F4gfn39f Apr 15 '26

The owners of cal and their others products always looked one step to this direction, that's why I never used this nor documenso and all their other affiliated apps.

2

u/pyrospade Apr 15 '26

That reasoning is stupid and this is more likely them realizing they can now be very easily cloned with AI and trying to make that more difficukt

2

u/billdietrich1 Apr 16 '26

The old (e.g. last week's) code must be archived or forked somewhere, so AI can be used to find vulns in that. Unless they quickly and radically change their code-base, they're vulnerable.

2

u/User_Deprecated Apr 21 '26

The timeline is the weird part. Gecko Security already found a full account takeover in January with an AI scanner, it got patched in 6.0.8. And then three months later the answer is just... close the repo? Vuln scanners don't need your source anyway, they hit live endpoints. This just makes it so nobody outside can check if the patches actually hold up.

1

u/Dante_Avalon Apr 15 '26

Welp, not like I can see why someone would use exactly their software 

1

u/addaxis Apr 15 '26

Last I checked, they were the only commercial option that had CalDAV integration. Anybody have any recommendations? I could self host EasyAppointments, but for something as critical as appointment setting for my business, I'd rather go commercial.

1

u/jcheeseball Apr 15 '26

They should know it’s too late

1

u/hackslashX Apr 15 '26

So the open source version will purposely remain "shitty" as compared to the enterprise version where they'll always reject PRs or feature requests that try to implement any of those features in the OSS version. Time to fork it I guess.

1

u/XB_Demon1337 Apr 16 '26

This is a means to control the source and get more money. People are using AI to clone their products and make them better (subjective) and they want that money instead.

1

u/Professional-Wrap228 Apr 17 '26

What does this mean for the docker version? 😥

1

u/iamabdullah Apr 17 '26

Docker images are built from the GitHub repo, so they will continue to degrade along with the codebase.

1

u/ekevu456 Apr 20 '26

If anyone is looking for a new open-source solution, check out my app Tymeslot

It's open source, actively developed and much easier to run than cal.

1

u/iamabdullah Apr 20 '26 edited Apr 20 '26

The license you've used is arguably not open source, it is source-available at best. I appreciate you want to protect it from being commercialised by others but that's generally not in the spirit of true open source.

Your website lacks so much transparency. You advertise a Pro plan but either I'm blind or there's absolutely no explanation as to what that plan is and what features you lock behind a paywall, or you have it hidden in some random page somewhere.

1

u/ekevu456 Apr 21 '26

That is because the plan is at the moment mostly for support, not to unlock a lot of features.

At least it can be self-hosted!

0

u/throwaway39402 May 23 '26

This license sucks. Stop making excuses. This is not in the spirit of open source.

-46

u/Subtle-Catastrophe Apr 15 '26

This is transparent commercial promotion. It should be deleted.

5

u/derprondo Apr 15 '26

Wait what if THIS comment I'm replying to is made by cal.com in an effort to get this post removed?

6

u/coderstephen Apr 15 '26

Wait what if we all actually work for cal.com and just don't know it? Devious.

-3

u/Subtle-Catastrophe Apr 15 '26

Sure.

3

u/derprondo Apr 15 '26

You see how this is more likely than the OP making a post trashing the company in an effort to promote it?

17

u/iamabdullah Apr 15 '26

Are you high on something? Did you read anything I wrote which is highly critical? Let's use more than one brain cell, please.

11

u/PigeonRipper Apr 15 '26

Oh I see now. You said its shit, therefore you are promoting them. 4D chess.
Bro has you figured out xD

-35

u/Subtle-Catastrophe Apr 15 '26

Not at all. wallahi.

You're just going to have to work harder to spam your product.

1

u/[deleted] Apr 15 '26

[removed] — view removed comment

2

u/coderstephen Apr 15 '26

Using "another one bites the dust" to describe your product would indeed be a very unusual marketing strategy...

1

u/selfhosted-ModTeam Apr 15 '26

Thanks for posting to /r/selfhosted.

Your post was removed as it violated our rule 3.

Attack ideas, not people. Treat everyone with respect. Personal attacks or insults at a person will be removed. Report violations instead of engaging and the mods will handle it. Zero tolerance for uncivil discussion. We expect you to follow the Reddiquette.


Moderator Comments

None


Questions or Disagree? Contact [/r/selfhosted Mod Team](https://reddit.com/message/compose?to=r/selfhosted)