I have used them in the past with no issues for personal sites. What are your concerns? In many aspects, a cert either "works" or it doesn't (in most cases, a SSL trusts the cert without warning). Generate a private and CSR that meet your security requirements (e.g. key length, cipher set, etc), submit it to StartSSL, and verify the resulting cert. If it meets your specs and is trusted by the SSL engines you use then…
My concern revolves around credibility. They took a beating after Heartbleed regarding the cost of revocation for certificates/credentials affected. While that is mostly a business decision on their end– it raises concerns about what their business is about. Nothing is "free", it just might not cost currency. "If you don't pay for the service, you are the service." Since I don't have experience with them I am looking…
In terms of "credibility", the issue comes down to how many browsers include their root cert by default. As far as I know, IE, Firefox, and Chrome include it meaning that it will be trusted by default.
The way they make money is selling other types of services such as wildcard and "green bar" certs. I think the folks running it want to see a wider use of SSL, and see providing free host-based certs as a good way to accomplish that goal. Bear mind, there zero cost to signing a cert ...