← Back to home
Comparison · Collab

CommaFeed vs Joplin

A side-by-side editorial comparison of CommaFeed and Joplin — release velocity, themes, recent moves, and the top alternatives to consider.

CommaFeed vs Joplin: at a glance

FeatureCommaFeedJoplin
SectorCollabCollab
Velocity score5.06.3
Sparks · 30d01
Top themesrss-reader, self-hosted, security-hardening, access-controlnote-taking, ai-integration, privacy, mcp
Last editorial update21d ago1d ago
WebsiteVisit →Visit →

What is CommaFeed?

CommaFeed's security pass turns inward, from hostile feeds to hostile users

CommaFeed's 7.x line has become a sustained security pass, shipped one fix per patch release. The newest, 7.3.2, closes a cross-user data exposure: users could star or tag entries that were not theirs and then read them, filed as GHSA-prfv-88mm-5gpg. Behind it sit Host header injection on the password recovery endpoint with a new commafeed.password-recovery-public-base-url setting, local address blocking made secure by default alongside Google Reader API support in 7.3.0, and javascript: URL filtering moved to parse time.

Read the full CommaFeed trajectory →

What is Joplin?

Joplin 3.7 ships AI chat, semantic search, and MCP integration — all off by default, all controllable by the user.

Joplin 3.7 is the product's first real AI release: an in-app chat panel for querying the currently open note, semantic (meaning-based) search across notebooks, and an MCP server that lets external AI assistants connect to Joplin's note graph. The implementation is privacy-first by design — AI is disabled by default, local models (Ollama, LM Studio) are explicitly supported, and cloud AI services only receive the specific note content relevant to a request rather than the full notebook. A companion documentation post published September 14 lays out the privacy model explicitly.

Read the full Joplin trajectory →

CommaFeed vs Joplin: editorial side-by-side

C
CommaFeed
COLLAB
5.0

CommaFeed's security pass turns inward, from hostile feeds to hostile users

◆ Current state

CommaFeed's 7.x line has become a sustained security pass, shipped one fix per patch release. The newest, 7.3.2, closes a cross-user data exposure: users could star or tag entries that were not theirs and then read them, filed as GHSA-prfv-88mm-5gpg. Behind it sit Host header injection on the password recovery endpoint with a new commafeed.password-recovery-public-base-url setting, local address blocking made secure by default alongside Google Reader API support in 7.3.0, and javascript: URL filtering moved to parse time.

◆ Where it's heading

The earlier fixes in this run all closed paths where something from outside the instance was trusted too far — feed URLs reaching internal addresses, proxied images, javascript: links, a request header shaping an outbound email. 7.3.2 is a different shape: nothing external is involved, the attacker is a legitimate signed-in user, and the flaw is an ownership check missing on a write path that then leaks through a read path. That is the class of bug you find once you start auditing multi-tenancy rather than input handling, and it suggests the review has moved past the perimeter into the authorization model that the 7.0.0 multi-user rework put in place.

◆ Prediction

If the audit is now working through ownership checks rather than input validation, the other per-user write paths — subscription and category mutations, saved searches — are the likely next findings. The pattern of shipping each fix as its own patch release with a GHSA reference should continue rather than batching them.

J
Joplin
COLLAB
6.3

Joplin 3.7 ships AI chat, semantic search, and MCP integration — all off by default, all controllable by the user.

◆ Current state

Joplin 3.7 is the product's first real AI release: an in-app chat panel for querying the currently open note, semantic (meaning-based) search across notebooks, and an MCP server that lets external AI assistants connect to Joplin's note graph. The implementation is privacy-first by design — AI is disabled by default, local models (Ollama, LM Studio) are explicitly supported, and cloud AI services only receive the specific note content relevant to a request rather than the full notebook. A companion documentation post published September 14 lays out the privacy model explicitly.

◆ Where it's heading

Joplin is repositioning from a sync-agnostic note-taking app into an AI-native knowledge base, differentiated by opt-in, local-first controls. The HMD Terra M preload partnership and the warrant canary point to a deliberate push toward privacy-conscious enterprise and professional users who distrust cloud-first tools. The MCP integration is particularly strategic: it makes Joplin's note graph accessible to external orchestration pipelines without locking into any particular AI provider.

◆ Prediction

The next major release will likely expand AI chat to multi-note context — currently limited to the open note — and add more configurable MCP tools. The HTR (handwritten text recognition) project from the 2024 French government partnership is also likely to appear in a near-term release.

Alternatives to CommaFeed and Joplin

Other Collab products tracked by Sparkpulse, ranked by recent ship velocity. Each card links to a full editorial trajectory and lets you pivot into a head-to-head comparison with either CommaFeed or Joplin.

See all CommaFeed alternatives → · See all Joplin alternatives →

Recent activity from CommaFeed and Joplin

Latest ship moves from both products, interleaved chronologically. ⚡ = editorial spark.

  1. 2d agoJoplinYour notes and AI: privacy first
  2. 16d agoJoplinWhat's new in Joplin 3.7
  3. 25d agoCommaFeedCross-user entry disclosure via starring and tagging closed
  4. 29d agoCommaFeedHost header injection closed on the password recovery endpoint
  5. 1mo agoCommaFeedGoogle Reader API support and secure-by-default local address blocking
  6. 1mo agoCommaFeedjavascript: URLs now filtered at parse time, not just in the renderer
  7. 2mo agoCommaFeedFeed-declared icons, starred-entry search, and image-proxy SSRF fix
  8. 4mo agoJoplinWhat's new in Joplin 3.6
  9. 5mo agoCommaFeedMobile unread count in the header plus a graceful refresh shutdown
  10. 6mo agoJoplinIntroducing our Warrant Canary
  11. 7mo agoJoplinJoplin will come preloaded on the HMD Terra M
  12. 8mo agoJoplinWhat's new in Joplin 3.5

Frequently asked questions

What is the difference between CommaFeed and Joplin?

They serve adjacent needs but don't currently overlap on shipped themes. Joplin is currently shipping more aggressively (velocity 6.3 vs 5.0), with 1 editorial sparks in the last 30 days against 0. See the at-a-glance table above for a side-by-side breakdown of velocity, recent sparks, and editorial themes.

Is CommaFeed better than Joplin?

Sparkpulse doesn't pick a winner — we score release velocity, not feature parity. Joplin is currently shipping more aggressively (velocity 6.3 vs 5.0), with 1 editorial sparks in the last 30 days against 0. For your specific use case, the alternatives sections above list other Collab products to evaluate alongside.

What are the best alternatives to CommaFeed?

Top CommaFeed alternatives in Collab are ranked by recent ship velocity. Browse the "CommaFeed alternatives" section above for the current picks, or visit /alternatives/commafeed for the full list with editorial commentary on each.

What are the best alternatives to Joplin?

Top Joplin alternatives in Collab are ranked by recent ship velocity. Browse the "Joplin alternatives" section above for the current picks, or visit /alternatives/joplin for the full list with editorial commentary on each.