Open-source project
LimeSurvey/LimeSurvey avatar
LimeSurvey/LimeSurvey

LimeSurvey: self-hosted surveys with a PHP stack and a GPL licence

🔥 LimeSurvey – A powerful, open-source survey platform. A free alternative to SurveyMonkey, Typeform, Qualtrics, and Google Forms, making it simple to create online surveys and forms with unmatched flexibility.

3,738 stars1,125 forksJavaScriptNOASSERTION

At a glance

What is it?
LimeSurvey is an open-source survey platform you install on your own PHP web server. It is the right tool when data residency and question logic matter more than a hosted dashboard, and the wrong one when nobody on the team wants to run a LAMP stack.
Who is it for?
Adopt LimeSurvey if you have a PHP-capable server, a database administrator, and a requirement to keep response data inside your own infrastructure; the README's minimal stack is Apache or nginx with PHP 8.1.29 or newer and MySQL 8.0, PostgreSQL 14, MariaDB 10.3.38 or MSSQL 2019. Do not adopt it if you want a survey tool with no server to patch, or if you need a support contract that the free download does not include.
Can I use it commercially?
Check first. The repository uses a licence we do not classify automatically, so read its LICENSE file before any commercial use.
Is it still maintained?
Yes. The repository last received commits 1 day ago.
What is it written in?
Mainly JavaScript, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on September 30, 2026, and from our analysis. They are not legal advice.

Editorial analysis

What LimeSurvey solves, and for whom

The problem LimeSurvey addresses is not "how do I build a form". It is "how do I run a survey programme without handing the response data to a vendor". The README frames the project as a free alternative to SurveyMonkey, Typeform, Qualtrics and Google Forms, and lists the audiences it has in mind: businesses, academic institutions, teachers, students, governments and financial institutes across 80+ countries. The common thread is an organisation that needs the questionnaire logic of a commercial tool but cannot or will not let a third party host the answers.

Two features in the README point at that audience directly. The first is GDPR compliance and data anonymisation, which only means something when you control the database. The second is the closed access mode, where participants get a personal link rather than an open URL, which is the shape of an employee survey or a patient questionnaire. Neither is exotic, but both are the reason someone picks a self-hosted tool over a hosted one.

The project has been around since 2006 according to its own README, and the repository is not archived: the last push was on 2026-09-23. That matters for a tool you plan to keep for years, because survey platforms accumulate question types, export formats and integrations that are expensive to migrate away from.

The PHP application, the React admin, and the RemoteControl API

The repository layout describes a conventional PHP web application. There is an index.php entry point, an admin/ directory, an application/ directory, an installer/, a plugins/ directory, themes/, locale/ for translations, and a vendor/ directory populated by Composer. The top-level composer.json and composer.lock sit next to package.json and yarn.lock, so the project has two dependency trees: PHP libraries on one side, front-end assets on the other.

The front end is not a single-page application. package.json lists jQuery 3.6, jQuery UI, Bootstrap 5.1, Select2, Chart.js, DataTables and Leaflet as runtime dependencies, with gulp, browserify, babelify and sass on the build side. That is the toolchain of a server-rendered application that ships its own bundled JavaScript, not of a React app talking to a JSON backend. The React topic on the repository refers to parts of the admin interface, not to the whole product.

The integration surface is the RemoteControl API, which the README says is exposed over XML-RPC and JSON-RPC. There is also an open-api-gen.php file at the repository root, which suggests the REST surface is generated from a specification rather than hand-written. Alongside it the README lists SAML, LDAP, SURFconext and REST API integrations, and a plugin system covering question themes, survey themes, audit logging, ExportR and ExportSTATAxml. If your institution already runs SAML or LDAP, those are the hooks that decide whether single sign-on is a configuration task or a development project.

Installing LimeSurvey on a PHP server and creating a first survey

The README does not give a step-by-step install procedure. It points at the stable release download page at community.limesurvey.org/downloads and warns that the development repository may contain versions that are not fully tested. So the honest first step is to get the archive from the release page rather than to clone master.

What the README does specify precisely is the environment. The minimal requirements are Apache 2.4 or newer, nginx 1.1 or newer, or any PHP-ready web server; PHP 8.1.29 or newer with the mbstring and PDO drivers; and one of MySQL 8.0, PostgreSQL 14, MariaDB 10.3.38 or MSSQL 2019. The recommended column adds php-fpm and the gd2, imap, ldap, zip and zlib extensions. Those extension names are the ones to check before you start, because a missing PDO driver shows up as a database connection failure during setup rather than as a clear error.

There is no install command in the README to copy. The document names the extensions and the database versions and stops there, which is why the environment check is a manual one: confirm that your PHP build reports the mbstring and PDO drivers and that your database server is at one of the versions listed above. If it is not, the installer under installer/ will fail partway through rather than tell you which requirement you missed.

Once the archive is unpacked into your web root and the database credentials are in place, the browser-based installer under installer/ runs the schema setup and creates the administrator account. The README does not publish a default username or password, so there is no credential to look up: the account is the one you create during installation. After login, the admin interface is where you create a survey, add questions from the 30+ question types, and attach skip logic or question branching. Sharing happens either through a public link, a QR code, or a closed-access personal link.

For scripted work, the RemoteControl API is the entry point. The README names the protocol but not the endpoint path or method signatures, so the manual at limesurvey.org/manual is where the actual call format lives.

Where LimeSurvey is the wrong tool

The first limitation is operational. LimeSurvey is software you host, which means you own the PHP upgrades, the database backups, the TLS certificates and the security patches. The README's own escape hatch is telling: it offers a hosted SaaS option for people who "don't want to host yourself". If your team has no one who can apply a PHP security release on a weekend, the free download is not actually cheaper than a hosted plan, it just moves the cost into unplanned work.

The second limitation is licence shape. LimeSurvey is GPL v2.0 with the option to use any later GPL version, and the README notes that the pictures and the LimeSurvey logo are registered trademarks of LimeSurvey GmbH. GPL is a copyleft licence. If you plan to embed the survey engine inside a proprietary product you distribute, that is a conversation for your legal team, not a detail you discover after shipping. Running it as a service for your own organisation is a different question from redistributing a modified build.

The third limitation is that the README is a feature list, not a specification. It claims 900+ survey templates, 80+ languages and WCAG 2.0 compliance, but it does not document performance characteristics, concurrency limits, or what happens to a running survey when you upgrade the application mid-fieldwork. If you are running a high-traffic study, that gap is the thing to test on your own hardware before the launch date, not after.

LimeSurvey compared with Google Forms and Qualtrics

The README positions LimeSurvey against four named products, and the differences are structural rather than cosmetic.

Google Forms is free and requires no server, but the responses live in Google's infrastructure and the questionnaire logic stops well short of what LimeSurvey offers. There is no equivalent of the RemoteControl API for programmatic survey manipulation, no LDAP or SAML integration for institutional single sign-on, and no plugin system for custom question types. If your survey is ten questions long and the data is not sensitive, Google Forms is the faster answer and LimeSurvey is overkill.

Qualtrics sits at the other end. It is a commercial platform with a support organisation behind it, which is exactly what the LimeSurvey download does not include. The trade is control for accountability: with LimeSurvey you can read the PHP source and move the data wherever you like, but when a survey breaks during fieldwork there is no account manager to escalate to, only the forums and the bug tracker at bugs.limesurvey.org. Teams that need a contractual SLA should price that difference honestly rather than treating the licence cost as the whole comparison.

The middle ground is LimeSurvey's own hosted SaaS, which the README promotes. It is the same feature set without the server administration, and it is worth knowing that the project itself offers it before you assume self-hosting is the only supported path.

Maintenance, upgrades and licence obligations

The repository is not archived and the last push was on 2026-09-23, so the codebase is receiving changes. That cuts both ways: you get fixes, and you also get a moving target. The README explicitly warns that the development repository "may contain versions that are not fully tested", which is the project telling you to track stable releases rather than master. For a survey that is open in the field, that distinction is the whole upgrade policy.

The dependency picture adds to the maintenance load. The front end pins Bootstrap at ~5.1.3 through both a dependency and a resolutions entry, and it pulls jQuery, jQuery UI, Select2 and a nestedSortable fork directly from a GitHub URL. Those pins are deliberate, but they mean a front-end upgrade is a coordinated change across gulp, browserify and sass, not a version bump. On the PHP side, composer.lock and vendor/ mean the same discipline applies.

On licensing, the README states GPL v2.0 with the option to use any later GPL version, and reserves the LimeSurvey name and logo as trademarks of LimeSurvey GmbH in Hamburg. The practical implication is that you can run, modify and redistribute the software under GPL terms, but you cannot present a modified build as the official LimeSurvey product. Whether your specific deployment triggers distribution obligations is a question for a lawyer, and the README does not attempt to answer it.

Editorial conclusion

Adopt LimeSurvey if you have a PHP-capable server, a database administrator, and a requirement to keep response data inside your own infrastructure; the README's minimal stack is Apache or nginx with PHP 8.1.29 or newer and MySQL 8.0, PostgreSQL 14, MariaDB 10.3.38 or MSSQL 2019. Do not adopt it if you want a survey tool with no server to patch, or if you need a support contract that the free download does not include. Before committing, verify two things: that your PHP build has the mbstring and PDO drivers the README lists, and that your organisation accepts GPL v2.0-or-later terms for a tool you may want to embed in a closed product.

Frequently asked questions

What is LimeSurvey used for?

The README describes it as an online survey platform for gathering feedback from customers, employees and stakeholders, for academic research and field studies, and for multilingual surveys. It is also aimed at organisations that prioritise privacy and GDPR compliance in data collection.

Is LimeSurvey free?

The README calls it a free and open-source platform and states that it is licensed under GPL v2.0 with the option to use any later GPL version. The project also sells a hosted SaaS option for organisations that do not want to run the server themselves.

How do I install LimeSurvey?

The README points to the latest stable release at community.limesurvey.org/downloads and warns that the development repository may contain versions that are not fully tested. You need a PHP-ready web server, PHP 8.1.29 or newer with mbstring and PDO drivers, and one of MySQL 8.0, PostgreSQL 14, MariaDB 10.3.38 or MSSQL 2019.

Is LimeSurvey safe to use for sensitive data?

The README lists GDPR compliance, data anonymisation, two-factor authentication and a closed access mode using personal invite links. Those features describe what the software supports; the security of a given deployment still depends on how the server and database are configured by whoever runs it.

Official sources

  1. Issues
  2. LimeSurvey/LimeSurvey on GitHub
  3. Project website
  4. README
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/limesurvey-limesurvey.svg)](https://hysenlabs.com/projects/limesurvey-limesurvey)