Emby

Emby is a personal media server application that allows users to organize, stream, and manage their own video, music, and photo collections across devices. It offers a freemium model with basic features free and advanced functionality like hardware transcoding and DVR requiring a paid Emby Premiere subscription.

35/ 100
Early Warning
2Squeezing UsersStable

Score generated by AI agents based on publicly cited evidence and reviewed by the project maintainer. Not independently validated.

Score History

MilestoneCriticalMajor
WMC Plugin Origins (2008–2015) · 3/100WMC Plugin OriginsEmby Rebrand & Freemium (2015–2017) · 8/100Emby &Rebrand…GPL Cracks Emerge (2017–2018) · 15/100Closed-Source Enclosure (2018–2021) · 22/100Closed-So…EnclosureProprietary Consolidation (2021–2023) · 27/100Proprieta…Consolida…Botnet Crisis (2023–2026) · 30/100BotnetCrisisMounting Vulnerabilities (2026–present) · 35/100Mount…1007550250200820122016202020242026-02WMC Plugin Origins (2008–2015) · 3/100Emby Rebrand & Freemium (2015–2017) · 8/100GPL Cracks Emerge (2017–2018) · 15/100Closed-Source Enclosure (2018–2021) · 22/100Proprietary Consolidation (2021–2023) · 27/100Botnet Crisis (2023–2026) · 30/100Mounting Vulnerabilities (2026–present) · 35/100381522273035MilestonesFounded (2008)Rebranded to Emby (2015)Closed-Source Transition (2018)Jellyfin Fork Created (2018)Events

Timeline events are AI-curated from public reporting. Score trajectory is derived from documented events.

WMC Plugin Origins
3/100
2008-01-01

Media Browser launched as a fully open-source GPLv2 plugin for Windows Media Center, created by Luke Pulverenti with community contributors. The project had no monetization, no paywalls, and no proprietary components. Minimal enshittification risk existed beyond the inherent lock-in of the Windows Media Center ecosystem and the informal governance structure of a volunteer-driven project.

Emby Rebrand & Freemium
8/100+5
2015-03-01

Media Browser rebranded to Emby and transitioned from a WMC plugin to a standalone client-server media platform. Luke Pulverenti went full-time, and the project introduced a Supporter/Premiere subscription model to fund development. Features like mobile sync and cinema intros became premium-only, establishing the freemium model. The codebase remained mostly open source with the GPLv2 server published on GitHub.

GPL Cracks Emerge
15/100+7
2017-08-01

Proprietary binary DLLs were discovered in the GitHub repository that prevented the server from compiling without them, raising GPL violation concerns while Emby still marketed itself as open source. Build scripts were made proprietary, meaning published binaries were non-reproducible. Users discovered persistent mb3admin.com phone-home behavior sending device IDs and account names. Client app repositories began disappearing from GitHub, signaling the coming enclosure.

Closed-Source Enclosure
22/100+7
2018-09-01

Version 3.5.3 formally closed the source code, announced casually in a bug report comment rather than through proper disclosure. The Jellyfin fork launched in December 2018 in direct response, with founders citing GPL violations, developer hostility, and code hiding. Emby Server 4.0 followed in January 2019, paywalling hardware-accelerated transcoding behind Premiere. Database schema changes made migration to Jellyfin impossible for anyone on 3.5.3+, creating a permanent switching cost barrier.

Proprietary Consolidation
27/100+5
2021-01-01

Emby settled into a steady cadence of proprietary releases (4.3 through 4.7), adding Live TV performance improvements, .NET 6.0 migration, and platform expansion. The SSRF vulnerability CVE-2020-26948 was disclosed and patched. Pricing remained stable at $119 lifetime. The free tier grew more restrictive as mobile and desktop app playback was limited to one-minute trials without Premiere or an app unlock purchase. Forum moderation drew complaints with reports of paying subscribers being banned while subscriptions continued.

Botnet Crisis
30/100+3
2023-06-01

A proxy header spoofing vulnerability known since February 2020 but unpatched in stable releases was exploited at scale, compromising approximately 1,200 Emby servers with credential-harvesting malware. Emby's remote shutdown of affected servers was responsible but also demonstrated the company's ability to remotely disable user-hosted software. The incident exposed the security risks of closed-source software that cannot be independently audited, and the three-year gap between vulnerability disclosure and exploitation highlighted slow patching practices.

Mounting Vulnerabilities
35/100+5
2026-02-12

CVE-2024-30931, CVE-2025-64113 (CVSS 9.3 Critical), and reports of remote exploits deleting user media drove a rapid escalation in D10 from 5 to 9 between 2023 and 2026. The free tier stabilized somewhat with the December 2024 announcement of free TV playback for five devices, but mobile and smart TV apps still require Premiere or per-app unlocks. The product continues receiving regular updates but the pattern of serious security vulnerabilities in closed-source code persists.

Alternatives

Free, open-source media server forked directly from Emby in 2018 when Emby went closed-source. No premium tier, no paywalls — all features are free. Moderate switch: your media files work as-is, but watch history and metadata require third-party migration tools since direct database import is not supported.

Plex46/100

The most popular personal media server with polished apps and easy remote access setup. Free tier is functional but increasingly cluttered with ad-supported streaming content you did not ask for. Plex Pass ($5/month or $120 lifetime) unlocks hardware transcoding and other features. Has its own enshittification trajectory.

Dimensional Breakdown

Summaries below were written by AI agents based on the cited evidence. They are editorial interpretations, not independent research findings.

User Value Erosion
Emby's free tier has been progressively restricted since the closed-source transition in 2018. As of December 2024, free TV playback is limited to 5 devices, and mobile/smart TV apps require either a per-app unlock (~$5) or an active Emby Premiere subscription for playback beyond a trial period. Core features like hardware-accelerated transcoding, offline downloads, live TV/DVR, and backup/restore are all paywalled behind Premiere ($4.99/month, $54/year, or $119 lifetime). User complaints cite recurring issues including broken Chromecast functionality, unreliable offline downloads on Android, Picture-in-Picture crashes on iOS, and difficulty establishing remote access. The app has become increasingly unreliable over time according to App Store reviewers. However, the web browser experience remains functional without payment, and the server continues to receive regular updates (4.9.3 stable in January 2026, 4.10 in beta), indicating ongoing development investment.
How It Got Here
Media Browser launched in 2008 as a free, community-driven Windows Media Center plugin with no restrictions on functionality. When Emby rebranded in 2015 and introduced the Supporter/Premiere subscription, early premium features like mobile sync and cinema intros were gated behind payment while the core server remained free. The closed-source transition in September 2018 accelerated feature paywalling: Emby Server 4.0 (January 2019) locked hardware-accelerated transcoding behind Premiere on all platforms except Nvidia Shield. Mobile and desktop app playback was restricted to one-minute trials without a subscription or per-app unlock purchase. By 2024, the free tier required navigating a confusing matrix of platform-specific restrictions, where per-app unlocks at roughly $5 each only removed playback limits on one device without granting server-side features like DVR or hardware transcoding. In December 2024, Emby introduced free TV playback for up to five devices, partially easing restrictions. However, App Store reviews cite increasing unreliability across platforms including Chromecast failures, iOS Picture-in-Picture crashes, and Roku app crashes. The web browser experience remains fully functional without payment, and version 4.9.3 (January 2026) demonstrates ongoing development investment.
Business Customer Exploitation
Shareholder Extraction
Lock-in & Switching Costs
Twiddling & Algorithmic Opacity
Dark Patterns
Advertising & Monetization Pressure
Competitive Conduct
Labor & Governance
Regulatory & Legal Posture

Dimension History

2008WMC Plugin Origins2015Emby Rebrand & Freemium2017GPL Cracks Emerge2018Closed-Source Enclosure2021Proprietary Consolidation2023Botnet Crisis2026Mounting VulnerabilitiesUser Value0122334Biz Exploit0011222Shareholder0111222Lock-in1123344Algorithms0001111Dark Patterns0112333Advertising0000000Competition0247777Labor/Gov1112223Regulatory1133469
Timeline (40 events)
major2008-01-01

Media Browser Project Launched as WMC Plugin

Luke Pulverenti initiated Media Browser as an open-source plugin for Windows Media Center, providing a user-friendly interface for organizing personal digital media collections. The project was released under GPLv2 and attracted community contributors over the following years.

major2013-01-01

Media Browser 3 Client-Server Architecture Introduced

After Windows 8 dropped Windows Media Center support, Pulverenti reimagined Media Browser with a client-server architecture, transforming it from a WMC plugin into a standalone media server. This was the foundation for what would become Emby, with over a year of intensive development before public release.

minor2014-01-01

Supporter Key System Introduced for Premium Features

Media Browser introduced a 'Supporter' key system allowing donors to access premium plugins and bonus features. This was the first step toward monetization of the formerly free project, though core functionality remained free and the server code stayed open source.

major2015-03-17

Media Browser Rebranded as Emby

Media Browser was officially rebranded to Emby (sounding like 'MB'), marking a strategic shift from a media center add-on to a full-fledged standalone media server platform. The new name accompanied a redesigned website at emby.media and expanded cross-platform client support.

major2015-04-01

Emby 3.0 Released with Standalone Server Architecture

Version 3.0.5572 launched Emby as a standalone server with web-based management, automatic metadata retrieval, real-time transcoding, and multi-device streaming. The release expanded support beyond video to include photos and music libraries, establishing the feature set that would define the product.

minor2015-09-28

Luke Pulverenti Goes Full-Time on Emby

In a Linux.com interview, founder Luke Pulverenti confirmed he had begun working full-time on Emby earlier in 2015, leaving his healthcare software career. He described Emby as an LLC funded by Supporter memberships and committed to keeping the project open source, stating 'that was the best way for the project to continue moving forward.'

major2016-08-01

Emby Premiere Subscription Formally Launched

Emby formalized its premium subscription as 'Emby Premiere' with monthly, annual, and lifetime options. A summer 2016 promotion offered lifetime subscriptions at $79.99. Premium features included mobile sync, hardware transcoding, cloud sync, and cinema intros, establishing the freemium model that persists today.

major2017-08-01

Emby Source Code Found to Contain Proprietary Binary Blobs

Community members discovered that Emby's GitHub repository contained proprietary binary-only DLL files (including Emby.Server.CinemaMode.dll, Emby.Server.Connect.dll, Emby.Server.MediaEncoding.dll, and Emby.Server.Sync.dll) without source code. The server could not compile without these blobs, raising GPL violation concerns while the project still marketed itself as open source.

major2017-08-01

Build Scripts Made Proprietary, Published Binaries Non-Reproducible

It was discovered that releases published via the Emby website were proprietary and could not be replicated from the public source code because the build scripts were also proprietary. This meant Emby was marketing itself as open source while distributing binaries that no one outside the team could independently build or verify.

major2017-09-01

Privacy Concerns Raised Over mb3admin.com Tracking

Users discovered that Emby servers regularly communicated with mb3admin.com, sending unique device IDs and user account names. Even with reporting and updating features disabled, dozens of connection attempts to mb3admin.com appeared in logs every minute. The mb3admin.com domain had been operational since 2012, but the extent of data collection was not transparently disclosed.

minor2017-10-01

Client App and Server Code Repositories Gradually Hidden

Emby began systematically removing various extensions and mobile app repositories from public access on GitHub. This progressive closing of previously open code preceded the formal closed-source transition and was later cited by Jellyfin founders as evidence of a deliberate enclosure strategy spanning several years.

minor2018-05-03

Emby Server 3.4 Released with Remote Access Controls

Version 3.4 introduced media conversion features, NVENC hardware transcoding improvements for Linux, and per-user remote access controls. The release also added .strm file resume support and automatic wake-on-recording for Windows. This was the last major feature release before the closed-source transition.

minor2018-08-03

Emby Server 3.5 Released with .NET Core Migration

Version 3.5 updated to .NET Core 2.1.2, ffmpeg 4.0.1, and improved library browsing performance. The release added Western Digital NAS support and a new blue radiance theme. This was the last version to maintain any pretense of open-source availability.

critical2018-09-20

Emby 3.5.3 Goes Fully Closed-Source

Version 3.5.3 was released with the entire server codebase relicensed as proprietary software. Luke Pulverenti announced the change in an offhand comment on a bug report rather than a formal announcement, stating 'we now have additions that are costing us money.' The community was not consulted. Open-source components were moved to standalone plugins only.

D8D4D10D9
Emby
major2018-12-07

Community Coordinates Fork Effort on GitHub

Joshua Boniface opened GitHub Issue #11 titled 'Upstream going closed-source,' documenting 'an extremely stark and chilling attitude from the core developers' and coordinating multiple independent fork efforts. Contributors including nvllsvm (who had maintained emby-unlocked patches), dcrdev, and JustAMan consolidated their work into a single project.

critical2018-12-08

Jellyfin Fork Announced as Free Software Alternative

The Jellyfin project was formally announced, forked from Emby 3.5.2 by co-founders Andrew Rabert and Joshua Boniface. The founders cited GPL violations, hostility toward community contributors, paywalls on formerly free features, and the hiding of client and server code. nvllsvm proposed the name 'JellyFin,' which was adopted. The fork attracted global contributors rapidly.

minor2018-12-09

Emby Forum Discussion Reveals Divided Community

A community forum thread titled 'Emby now closed-source..?' revealed deep divisions. Some users accepted the change given developer dedication, while others felt betrayed for having chosen Emby specifically for its open-source credentials. Critics noted Luke buried the announcement in a bug report comment rather than making a formal disclosure.

major2019-01-14

Emby Server 4.0 Released with Hardware Transcoding Paywall

The first fully closed-source major release introduced rewritten hardware transcoding supporting QuickSync, Nvidia, DXVA, VAAPI, and MediaCodec. However, hardware-accelerated transcoding was paywalled behind Emby Premiere on all platforms except Nvidia Shield and Western Digital. New live TV guide data and transcoding throttling were also added.

major2019-01-15

Jellyfin Documents Emby Database Migration Incompatibilities

Jellyfin developers documented that direct database migration from Emby 3.5.3+ was not supported due to schema incompatibilities. Users migrating were advised to start fresh with a new library scan, losing watched status, custom metadata, collections, and playlists. This effectively created a switching cost barrier between the two platforms.

minor2019-08-09

Emby Server 4.2.1 Released

Version 4.2.1 continued iterating on the closed-source 4.x line with bug fixes and improvements. The release cadence demonstrated that Emby maintained active development despite the community split with Jellyfin, though the contributor base was now limited to paid staff rather than the broader open-source community.

minor2019-11-26

Emby Server 4.3 Released with Subtitle Improvements

Version 4.3 brought improvements to subtitle handling, graphical subtitle overlay fixes, library scan path normalization, and various other fixes. The release continued Emby's pattern of incremental improvement on the proprietary codebase.

minor2020-09-22

Emby Server 4.5 Released with Playback Rate Controls

Version 4.5 added adjustable subtitle offset and playback rate in the web player, updated to .NET Core 3.1.7, re-activated HTTP/2 features, and improved Live TV guide scrolling performance. Database and HTTP server performance improvements were also included.

major2020-12-09

SSRF Vulnerability Disclosed in Emby Server (CVE-2020-26948)

CVE-2020-26948 revealed that Emby Server before 4.5.0 was vulnerable to server-side request forgery via the Items/RemoteSearch/Image ImageURL parameter. The vulnerability allowed attackers to send crafted requests generating connections to malicious servers, potentially leading to data exfiltration and unauthorized access to internal networks.

minor2021-05-21

Emby Server 4.6 Released with Live TV Performance Improvements

Version 4.6 delivered a 70% improvement in xmltv guide data refresh performance (from 2.5 hours to 45 minutes on a 4000-channel guide). Multi-select management features were added to list views. The release reinforced Emby's strength in Live TV/DVR functionality, a key differentiator from Jellyfin.

minor2022-05-01

Emby Server 4.7 Released with .NET 6.0 and ffmpeg 5.0

Version 4.7 brought major framework updates to .NET Core 6.0 and ffmpeg 5.0, adding log anonymization, now-playing screen style options, and playlist import capabilities. The release demonstrated continued technical investment in the proprietary codebase, though the feature gap with Jellyfin continued narrowing.

minor2022-08-01

Paying Subscriber Banned from Emby Forums

A paying Emby Premiere subscriber reported being banned from the support forums while subscription payments continued. The Emby support response was reportedly 'this is not AT&T, we don't have to deal with you.' The user had no alternative channel for support despite maintaining an active paid subscription.

critical2023-05-15

Botnet Attack Compromises 1,200 Emby Servers

Attackers exploited a proxy header spoofing vulnerability (known since February 2020 but unpatched in stable releases) combined with insecure admin configurations to infiltrate approximately 1,200 Internet-exposed Emby servers. The attackers installed a malicious plugin (helper.dll/EmbyHelper.dll) that harvested login credentials of all users who signed into compromised servers.

major2023-05-25

Emby Remotely Shuts Down 1,200 Compromised Servers

Emby pushed a server update that detected the malicious plugin and prevented affected servers from starting until the plugin was removed. The team described this as shutting down a botnet 'within 60 seconds.' While the remote shutdown was a responsible security response, it also demonstrated that Emby has the technical capability to remotely disable user-hosted servers.

minor2023-06-15

Full Disclosure Security Incident Report Published

Emby published a detailed incident report for the May 2023 botnet attack, explaining the proxy header spoofing vulnerability, the attack vector, and the remediation steps. The disclosure was transparent and comprehensive, demonstrating responsible security incident handling even though the underlying vulnerability had been known for over three years before it was exploited at scale.

minor2023-07-01

Emby Server 4.8 Released

Version 4.8 was released with new features and improvements following the botnet incident. The release included security hardening measures addressing the proxy header vulnerability that had been exploited. The version also introduced new client app development capabilities.

major2024-04-01

Stored XSS Vulnerability Disclosed (CVE-2024-30931)

CVE-2024-30931 revealed a stored cross-site scripting vulnerability in Emby Server 4.8.3.0 in the notifications.html component. The FriendlyName parameter lacked sufficient validation, allowing attackers to craft payloads that executed when any user viewed notifications. The attack chain could escalate a regular user to platform administrator by stealing admin tokens.

minor2024-04-21

Emby Server 4.8.4.0 Patches XSS Vulnerability

Emby released version 4.8.4.0 to address CVE-2024-30931, adding proper input validation to the notification creation request. The fix was released within approximately two weeks of public disclosure, demonstrating responsive patching for known vulnerabilities.

minor2024-12-01

Emby Theater Discontinued, Replaced by New Windows App

Emby Theater Desktop was discontinued and replaced by a new unified 'Emby' app for Windows and Xbox, combining the best features of the desktop Theater app and the Windows Store version. The new app used MPV player for enhanced video playback. While technically an improvement, the forced migration removed a familiar client that some users preferred.

minor2024-12-27

Free TV Playback for Five Devices Announced

Emby announced free playback for up to five TV devices per server, easing the transition from the old Android TV-only app to the new standard Android app. Emby Premiere device limits were also increased from 25 to 30 (standard), 45 to 50, and 75 to 80 (extended plans). Previously purchased app unlocks continued to be honored.

major2025-10-01

Remote Access Exploit Reportedly Deleting User Media

Emby community forum reports described a possible remote access exploit that was deleting media from Emby servers. The reports indicated that external attackers were able to access and delete files on user-hosted servers, raising concerns about another security vulnerability in the closed-source codebase.

major2025-10-30

Remote Code Execution Vulnerability Disclosed (CVE-2025-64325)

CVE-2025-64325 (CVSS 8.4) revealed that a malicious user could send manipulated authentication requests with crafted X-Emby-Client values that were added to the admin dashboard without sanitization. Exploitation could grant attackers persistence on the server machine through malicious scripts with admin permissions. All versions prior to 4.8.1.0 were affected.

major2025-11-01

Belgium CERT Issues High Severity Warning for Emby

The Belgian Centre for Cybersecurity (CCB) issued a warning about a high-severity remote code execution vulnerability in Emby Server, advising all users to patch immediately. The advisory classified the vulnerability as a significant threat requiring urgent action, marking the first time a national cybersecurity agency issued a specific warning about Emby.

minor2025-11-25

Emby Premiere Lifetime Discounted to $99, Signals Price Increase

Neowin reported that Emby Premiere lifetime was discounted to $99, 'likely the last time price will be so low.' The messaging implied an upcoming permanent price increase for the lifetime tier, which had been at $119 with periodic $99 promotions. This signaled a shift toward extracting more revenue from the subscriber base.

critical2025-12-06

Critical Admin Takeover Vulnerability Disclosed (CVE-2025-64113)

CVE-2025-64113 (CVSS 9.3 Critical) revealed that an attacker could gain full administrative access to any Emby server with no preconditions beyond network access, through a weak password recovery mechanism in the ForgotPassword API. The vulnerability was straightforward to exploit and required no special privileges or user interaction. All versions up to 4.9.1.80 (stable) and 4.9.2.6 (beta) were affected.

minor2026-01-01

Emby Server 4.9.3 Released as Latest Stable

Version 4.9.3.0 was released as the current stable build, with 4.10 entering beta. The release updated Intel drivers on Linux, added user-configurable auto remote quality, and included library and music transcoding fixes. Development continued at a steady pace despite the mounting security vulnerability track record.

Evidence (41 citations)

D2: Business Customer Exploitation

D7: Advertising & Monetization Pressure

Scoring Log (4 entries)
deep-enrichment-reset2026-03-19

Stripped for Phase 2 re-enrichment

Deep Enrichment2026-03-19
Alternatives Review2026-02-21GOOD
Initial Scoring2026-02-12