Maddy
A one-binary mail server learning to behave like production infrastructure.
A side-by-side editorial comparison of Friendica and Roundcube — release velocity, themes, recent moves, and the top alternatives to consider.
Friendica keeps betting on being the fediverse node that speaks everyone else's protocols.
Friendica is a self-hosted decentralised social platform, released on calendar versions two or three times a year with codenames and a consistent structure: a handful of highlights, a security-fix credit, and a pointer to the changelog. The recent run — 2023.12, 2024.03, 2024.08, 2024.12, 2026.01, 2026.05 — shows the cadence thinning, with a full year between 2024.12 and 2026.01. Nearly every release credits externally reported security issues, most recently from Doyensec working with Mastodon.
After four years, Roundcube 1.7 lands — and the release stream is otherwise all CVEs
Roundcube maintains two lines in lockstep: 1.6 as LTS and 1.7 as stable, with security fixes released to both on the same day. The vulnerability stream is heavy and varied — stored XSS via an unescaped attachment MIME type (CVE-2026-54432), a pre-auth SQL injection in the virtuser_query plugin, CSS injection through SVG animate, SSRF bypasses via local address URLs, an infinite loop in the TNEF decoder. Version 1.7.0, released in May after almost four years of development, is the only feature release in the window.
Friendica is a self-hosted decentralised social platform, released on calendar versions two or three times a year with codenames and a consistent structure: a handful of highlights, a security-fix credit, and a pointer to the changelog. The recent run — 2023.12, 2024.03, 2024.08, 2024.12, 2026.01, 2026.05 — shows the cadence thinning, with a full year between 2024.12 and 2026.01. Nearly every release credits externally reported security issues, most recently from Doyensec working with Mastodon.
Two lines of work dominate. The first is connectors: an initial Bluesky bridge in 2023.05 made bi-directional by 2023.12, Tumblr support maintained throughout, and ATproto account integration plus Bridgy Fed support improved in 2026.05. The second is Channels — the user-defined algorithm for sorting the network stream — introduced in 2023.12 and given performance and sorting work in every release since. Running against both is a deliberate pruning of legacy: OStatus dropped in 2024.12 after the project measured how few servers still needed it, and the fancybox addon deprecated alongside it.
Expect the next release to continue the ATproto and Bridgy Fed integration work and further Channels performance tuning, with the accessibility review started in 2026.01 producing more fixes. Given the year-long gap before 2026.01, the cadence itself is the uncertain part.
Roundcube maintains two lines in lockstep: 1.6 as LTS and 1.7 as stable, with security fixes released to both on the same day. The vulnerability stream is heavy and varied — stored XSS via an unescaped attachment MIME type (CVE-2026-54432), a pre-auth SQL injection in the virtuser_query plugin, CSS injection through SVG animate, SSRF bypasses via local address URLs, an infinite loop in the TNEF decoder. Version 1.7.0, released in May after almost four years of development, is the only feature release in the window.
The arc is a long-lived webmail codebase paying down structural risk. 1.7.0's headline changes are defensive rather than user-facing: a mandatory public_html/ entry point so installations aren't exposed by default, improved OAuth2/OIDC support including discovery and logout, removed code bloat and automated code style and quality checks. Everything since has been paired security releases across both lines, several of them reporting classes of bug — sanitizer bypasses, injection through plugin queries — that the 1.7 hardening work is aimed at. Expect the security cadence to stay high while the 1.6 LTS remains supported.
Expect continued same-day paired security releases on 1.6 and 1.7, with 1.7.x accruing incremental OIDC and sanitizer hardening before any 1.8 work becomes visible.
Other Comms products tracked by Sparkpulse, ranked by recent ship velocity. Each card links to a full editorial trajectory and lets you pivot into a head-to-head comparison with either Friendica or Roundcube.
A one-binary mail server learning to behave like production infrastructure.
The original federated social network now ships roughly once every two years.
Six releases, and every one of them is a security update in some form.
Renamed Element Classic, this client now ships one small fix every few months
Twilio is selling trust: branded calls, scoped keys, and stricter sender vetting.
Notion is turning Custom Agents into event-driven workers with their own runtime and billing.
See all Friendica alternatives → · See all Roundcube alternatives →
Latest ship moves from both products, interleaved chronologically. ⚡ = editorial spark.
Both compete on the same themes — self-hosted — within Comms. Roundcube is currently shipping more aggressively (velocity 5.0 vs 0.0), with 0 editorial sparks in the last 30 days against 0. See the at-a-glance table above for a side-by-side breakdown of velocity, recent sparks, and editorial themes.
Sparkpulse doesn't pick a winner — we score release velocity, not feature parity. Roundcube is currently shipping more aggressively (velocity 5.0 vs 0.0), with 0 editorial sparks in the last 30 days against 0. For your specific use case, the alternatives sections above list other Comms products to evaluate alongside.
Top Friendica alternatives in Comms are ranked by recent ship velocity. Browse the "Friendica alternatives" section above for the current picks, or visit /alternatives/friendica for the full list with editorial commentary on each.
Top Roundcube alternatives in Comms are ranked by recent ship velocity. Browse the "Roundcube alternatives" section above for the current picks, or visit /alternatives/roundcube for the full list with editorial commentary on each.