Flame
Self-hosted dashboard that finished its feature arc and stopped shipping in 2023.
A side-by-side editorial comparison of CommaFeed and Document360 — release velocity, themes, recent moves, and the top alternatives to consider.
| Feature | CommaFeed | Document360 |
|---|---|---|
| Sector | Collab | Collab |
| Velocity score | 5.0 | 6.3 |
| Sparks · 30d | 0 | 1 |
| Top themes | rss-reader, self-hosting, security-hardening, api-interop | api, oauth, mcp, knowledge base |
| Last editorial update | 2h ago | 21h ago |
| Website | Visit → | — |
A self-hosted RSS reader that now spends most of its release notes on security.
CommaFeed is a self-hosted Google Reader replacement that has spent the 6.x-to-7.x stretch rebuilding its trust boundaries rather than its feature list. SSRF protection has been tightened in four consecutive releases, feed parsing now strips javascript: URLs before they reach the database, and OPML imports are filtered against import-time abuse. The 7.x line pairs that with client interop: Fever API, ReadKit compatibility, and now the Google Reader API.
Document360 rebuilds its public API and turns docs into an agent-readable surface.
Document360 ships a dated release every two to four weeks and the last six months have been dominated by two threads: making the knowledge base machine-consumable, and hardening enterprise access control. The AI thread runs from the March MCP server through publishing and workflow tools in June and per-reader-group AI restrictions this month; the access thread runs SCIM provisioning, multiple JWT configurations, and reader permission inheritance. This release adds a ground-up API v3 with OAuth 2.0 and scoped keys.
CommaFeed is a self-hosted Google Reader replacement that has spent the 6.x-to-7.x stretch rebuilding its trust boundaries rather than its feature list. SSRF protection has been tightened in four consecutive releases, feed parsing now strips javascript: URLs before they reach the database, and OPML imports are filtered against import-time abuse. The 7.x line pairs that with client interop: Fever API, ReadKit compatibility, and now the Google Reader API.
The project is positioning itself as a sync backend other people's apps talk to, not just a web reader. Each release adds another protocol or client fix while hardening the assumption that an instance may be publicly exposed with untrusted users on it. The 7.0.0 swap from JEXL to sandboxed CEL and the 7.3.0 flip of blockLocalAddresses to a secure default both trade self-hoster convenience for a safer out-of-the-box posture.
Expect continued client-protocol coverage and further SSRF narrowing; the recurring pattern in these entries is that every new fetch path gets a follow-up hardening release.
Document360 ships a dated release every two to four weeks and the last six months have been dominated by two threads: making the knowledge base machine-consumable, and hardening enterprise access control. The AI thread runs from the March MCP server through publishing and workflow tools in June and per-reader-group AI restrictions this month; the access thread runs SCIM provisioning, multiple JWT configurations, and reader permission inheritance. This release adds a ground-up API v3 with OAuth 2.0 and scoped keys.
The product is being rebuilt around programmatic access rather than portal usage. MCP made the knowledge base writable by an assistant, llms.txt made it discoverable to crawlers, copy-as-Markdown and open-in-ChatGPT made articles portable, and API v3 now gives all of that a permission-aware substrate the old v1/v2 endpoints could not support. The same permission model is showing up on the reader side too — Eddy AI features are now gated per reader group — so authorization is becoming the shared spine across API, AI, and reader access.
Expect the advanced API v3 endpoints to keep expanding as a paid add-on and the MCP server to be re-plumbed onto v3's scoped-key model, since MCP currently sits outside the new authorization scheme. A v1/v2 deprecation notice is the other likely follow-up.
Other Collab products tracked by Sparkpulse, ranked by recent ship velocity. Each card links to a full editorial trajectory and lets you pivot into a head-to-head comparison with either CommaFeed or Document360.
Self-hosted dashboard that finished its feature arc and stopped shipping in 2023.
SiYuan's v3.8.0 train restates one AI feature set across seven consecutive builds.
Jellyfin renumbers to 12.0 and spends the whole cycle paying down its backend rewrite.
Teable is spending its release budget making bring-your-own-database failures survivable.
NetNewsWire rebuilt Feedly sync to stop getting its own users rate-limited.
Happeo's feed is a buyer-education funnel, not a changelog — no shipped work is visible.
See all CommaFeed alternatives → · See all Document360 alternatives →
Latest ship moves from both products, interleaved chronologically. ⚡ = editorial spark.
They serve adjacent needs but don't currently overlap on shipped themes. Document360 is currently shipping more aggressively (velocity 6.3 vs 5.0), with 1 editorial sparks in the last 30 days against 0. See the at-a-glance table above for a side-by-side breakdown of velocity, recent sparks, and editorial themes.
Sparkpulse doesn't pick a winner — we score release velocity, not feature parity. Document360 is currently shipping more aggressively (velocity 6.3 vs 5.0), with 1 editorial sparks in the last 30 days against 0. For your specific use case, the alternatives sections above list other Collab products to evaluate alongside.
Top CommaFeed alternatives in Collab are ranked by recent ship velocity. Browse the "CommaFeed alternatives" section above for the current picks, or visit /alternatives/commafeed for the full list with editorial commentary on each.
Top Document360 alternatives in Collab are ranked by recent ship velocity. Browse the "Document360 alternatives" section above for the current picks, or visit /alternatives/document360 for the full list with editorial commentary on each.